Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit

Kratos Phishing-as-a-Service Platform Dismantled in (TL-2026-1613), also tracked as Operation Olympus Blade, is a medium-severity campaign, first published 2026-07-22. It is attributed to Kratos PhaaS Operator with medium confidence, affects Microsoft Microsoft 365 / Microsoft Online authentication, maps to 23 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-1613

Threat ID
TL-2026-1613
Also known as
Operation Olympus Blade, Kratos PhaaS Takedown
Severity
MEDIUM
Status
MITIGATED
Category
CAMPAIGN
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kratos PhaaS Operator
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, retail, health, industrial, legal, education, government administration, finance
Target regions
united states of america, germany, spain, 039 - Southern Europe, Europe
Detection rules
9
Indicators of compromise
23

Malware and tooling in Kratos Phishing-as-a-Service Platform Dismantled in

Malware and tooling: Kratos, Kratos operator panel

German (BKA/ZIT Frankfurt), US, and Indonesian law enforcement dismantled Kratos, a Node.js-based AiTM (adversary-in-the-middle) phishing-as-a-service platform sold via a website and Telegram shop that let over 1,800 criminal franchisees run roughly 15,000 Microsoft 365-themed credential-and-session-cookie theft campaigns per month against victims in 30-35 countries. Authorities seized 200+ servers and arrested the alleged developer/administrator in Indonesia; the operator had earned at least €300,000 in subscription revenue since 2024.

How Kratos Phishing-as-a-Service Platform Dismantled in works

Kratos is a Phishing-as-a-Service (PhaaS) platform, active since at least September 2025 (with kit-lineage tracing back further under aliases SneakyLog/Sneaky 2FA), that industrialized adversary-in-the-middle (AiTM) credential and session theft against Microsoft 365 accounts. Operators purchased subscription access via a dedicated website and a Telegram-based shop, then used a central operator dashboard to configure and launch campaigns without needing to write or host any phishing code themselves — 'even low-skill actors could point a working AiTM kit at a target,' per reporting.

The kit offered operators a choice of two delivery modes from its 'Deploy' subdomain: a simpler PHP-based static Office 365 credential-harvesting page, or a Node.js reverse-proxy server that relays the victim's real-time login transaction to Microsoft's actual authentication endpoints (login.live.com / microsoftonline.com) while transparently capturing the resulting authenticated session cookie. Because the proxy relays a genuine Microsoft authentication flow, any MFA challenge the victim completes is satisfied against the real Microsoft service — the operator never needs to defeat MFA directly, only to capture the session cookie issued at the end of the transaction. That cookie alone is sufficient to assume the victim's authenticated session (T1550.004 Use Alternate Authentication Material: Web Session Cookie), which survives password resets and requires explicit session/token revocation to remediate.

Lures were highly varied and multi-staged: phishing emails impersonated document-sharing and productivity notifications ('User N has shared a document with you', 'Sign the document via DocuSign', 'An invoice has been sent', 'Notice of charge - [6-digit number]'), often routed victims through trusted intermediary platforms (SharePoint, OneDrive, Canva, Tilda, Microsoft Forms) before redirecting to the actual phishing page, and used six distinct payload delivery mechanisms: direct links, personalized QR codes (including QR codes embedded in fake W-2 tax documents in a February 10 campaign targeting ~100 US manufacturing/retail/healthcare organizations), weaponized HTML/SVG attachments, ICS calendar invites, RFC-compliant EML files, and PDF/DOCX documents with embedded QR codes. Adobe Creative Cloud/Document Cloud invoice-urgency lures were also used as a secondary brand alongside the primary Microsoft 365 theme.

The kit built in substantial anti-analysis and anti-bot tradecraft: CAPTCHA gating (Cloudflare Turnstile, reCAPTCHA, hCaptcha) to filter sandboxes and automated scanners before serving the real phishing payload; an animated 'Loading in progress…' envelope overlay on a blurred fake document as a visual fingerprint/stall; three-attempt password-entry limiting before redirecting away; geographic/device-type victim filtering via geoplugin.net and VPN/proxy detection; obfuscated JavaScript (a 'V2' generation of the kit); and dynamic domain generation across low-cost TLDs (.horse, .cfd, .sbs, .online) plus abuse of compromised legitimate WordPress sites (observed German .de and Spanish .es domains) and Cloudflare-fronted infrastructure to mask origin hosting. Backend hosting spanned Azure, Google Cloud, and the bulletproof/VPS provider Host4Geeks. Stolen data was exfiltrated to operators via Telegram bot API (api.telegram.org) — blending exfiltration traffic with legitimate encrypted Telegram traffic to evade DPI — or delivered as JSON via email; the operator panel itself was protected by a master password plus Telegram-based 2FA. The architecture was described as 'decoupled,' separating the victim-facing phishing front end from backend credential storage so harvested data remained accessible even after individual phishing URLs were taken down.

Security researchers identified a durable, high-confidence detection signature: Kratos login pages consistently load a paired pair of static assets, barr.svg and lg.svg, and POST stolen credentials to predictable backend endpoints that evolved across kit versions (V0: */PTT/SOft/mini.php; V1: */next.php, */nex.php, */n3xt.php; V2: */save.php) — a pattern researchers reported achieving ~90% recall with a near-zero false-positive rate. Kratos infrastructure was also observed sharing hosting with other AiTM PhaaS kits in the same criminal ecosystem, including Tycoon (Tycoon2FA), Flowerstorm, Sneaky2FA, and EvilProxy.

By law enforcement's account, the platform's ~1,800 paying criminal subscribers launched approximately 15,000 phishing campaigns per month, generating hundreds of thousands of victims across 30-35 countries (concentrated in Southern Europe, particularly Spain, as well as the US); one law-enforcement figure put confirmed identified victims at approximately 850 across 35 countries, with targeted sectors including manufacturing, retail, and healthcare in the US and industrial, legal, and education verticals in Europe. The operation, publicly branded by investigators as 'Operation Olympus Blade,' was led by Frankfurt's Central Office for Combating Internet Crime (ZIT) and Germany's Federal Criminal Police Office (BKA), supported by US law enforcement (FBI), with the arrest of the alleged Kratos developer/administrator physically executed by Indonesian police. More than 200 servers supporting the platform were seized/nulled, and the FBI took over ownership of the seized Kratos website domain, replacing it with a law-enforcement seizure banner. Authorities estimated the operator earned at least €300,000 (~$342,000) in subscription revenue since 2024. ZIT head Dr. Benjamin Krause stated the takedown reflected a strategy of 'disruptive law enforcement,' and BKA cybercrime head Carsten Meywirth warned that 'anyone who steals login credentials online using fake websites shouldn't feel safe.'

The takedown disrupted Kratos's central infrastructure and its administrator, but law enforcement acknowledged this does not eliminate the platform's roughly 1,800 existing customers, who retain copies of kit code and may migrate to sibling AiTM kits (Tycoon2FA, Sneaky2FA, EvilProxy, Flowerstorm) that already share infrastructure with Kratos. Defensive recommendations from responders center on phishing-resistant MFA (FIDO2/WebAuthn passkeys, which are immune to session-cookie-relay AiTM attacks because they are bound to the origin), monitoring for anomalous Microsoft 365 sign-in patterns (impossible travel, new device/session anomalies), auditing for suspicious OAuth application grants and inbox/mailbox rule changes (common BEC follow-on indicators after session hijack), and blocking/monitoring the identified static-asset and endpoint signatures at the web-proxy/EDR layer.

MITRE ATT&CK techniques used in TL-2026-1613

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

Persistence

T1078 Valid Accounts; T1098 Account Manipulation

command-and-control

T1090 Proxy

Collection

T1119 Automated Collection

Initial Access

T1199 Trusted Relationship; T1566 Phishing

Impact

T1531 Account Access Removal

lateral-movement

T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

stealth

T1684.001 Impersonation

Affected products and versions in Kratos Phishing-as-a-Service Platform Dismantled in

  • Microsoft — Microsoft 365 / Microsoft Online authentication (login.live.com, microsoftonline.com)
    Vulnerable versions: N/A - social engineering / AiTM session theft, not a software vulnerability
    Fixed in: N/A - mitigated via phishing-resistant MFA and session/token revocation, not a patch
  • Adobe — Adobe Creative Cloud / Document Cloud (impersonated as phishing lure brand)
    Vulnerable versions: N/A - brand impersonation lure
    Fixed in: N/A

Remediation for Kratos Phishing-as-a-Service Platform Dismantled in

Immediate actions

  • Force session/token revocation and password resets for any Microsoft 365 account with sign-ins from suspicious IPs or with anomalous impossible-travel patterns since September 2025
  • Block/monitor for the identified Kratos static asset pair barr.svg and lg.svg co-occurring on a single page at the web proxy / SWG layer
  • Alert and block on POST requests to phishing exfiltration paths matching */PTT/SOft/mini.php, */next.php, */nex.php, */n3xt.php, */save.php, and /PTT/SOft
  • Audit Microsoft 365 tenants for unauthorized OAuth application consents and inbox/mailbox forwarding rule changes created after any suspected AiTM session compromise
  • Add identified Kratos-linked domains and IPs to email/web gateway blocklists

Workarounds

  • Where FIDO2/passkey rollout is not yet complete, enforce Conditional Access location- and device-compliance-based restrictions on Microsoft 365 sign-in as an interim AiTM mitigation

Longer-term hardening

  • Deploy phishing-resistant, origin-bound MFA (FIDO2/WebAuthn security keys or platform passkeys) for all Microsoft 365 and other high-value SaaS accounts, since AiTM session-cookie relay defeats OTP/push-based MFA
  • Enable Conditional Access sign-in risk policies and continuous access evaluation (CAE) in Microsoft Entra ID to shorten the usability window of stolen session tokens
  • Deploy DNS/browser-isolation controls for newly-registered and low-cost TLD domains (.horse, .cfd, .sbs, .online) commonly abused for disposable phishing infrastructure
  • Implement user awareness training specifically addressing document-share, DocuSign, invoice, and QR-code phishing lures, including QR codes embedded in PDF/W-2-style attachments
  • Monitor for shared hosting/infrastructure overlap with sibling AiTM kits (Tycoon2FA, Sneaky2FA, EvilProxy, Flowerstorm) since displaced Kratos customers are likely to migrate to these platforms

Timeline of Kratos Phishing-as-a-Service Platform Dismantled in

  • Law enforcement estimates the Kratos operator began earning subscription revenue from the platform, eventually totaling at least €300,000 by the time of takedown.
  • Microsoft Threat Intelligence begins tracking the same underlying AiTM kit lineage under the name 'SneakyLog,' documenting credential and 2FA/session-cookie theft campaigns against Microsoft 365 accounts.
  • Security researchers confirm the Kratos operator panel and AiTM kit infrastructure has been active in this form since at least this date.
  • Kratos V1 samples become visible in the ANY.RUN interactive sandbox for the first time (93 recorded analysis sessions in January), marking the earliest independently documented detection point for the kit.
  • Kratos-linked actors run a tax-themed W-2/QR-code phishing campaign against roughly 100 organizations, mostly in the US, spanning manufacturing, retail, and healthcare sectors, redirecting victims to fake Microsoft 365 login pages.
  • KnowBe4 Threat Labs publishes an analysis identifying distinct Q1 2026 Kratos campaign clusters and documenting the kit's lure diversity and industrialized subscription model.
  • ANY.RUN sandbox telemetry shows Kratos V1 analysis sessions climbing from 90 in February to 393 in June 2026, evidencing rapidly accelerating in-the-wild adoption of the kit in the months before takedown.
  • ANY.RUN publishes a detailed technical writeup of the Kratos AiTM kit's V0/V1/V2 version evolution, exfiltration endpoint patterns, and the barr.svg/lg.svg detection signature.
  • Kratos is still observed actively offering phishing-as-a-service subscriptions shortly before the takedown.
  • ZIT head Dr. Benjamin Krause and BKA cybercrime head Carsten Meywirth issue public statements characterizing the action as 'disruptive law enforcement' and warning credential-phishing operators they 'shouldn't feel safe.'
  • BKA, ZIT Frankfurt, US law enforcement, and Indonesian police execute Operation Olympus Blade: over 200 Kratos servers are seized/taken offline, the Kratos website domain is seized and transferred to FBI ownership, and the alleged developer/administrator is arrested in Indonesia.
  • Takedown is publicly reported by Help Net Security, The Register, The Hacker News, GBHackers, SC Media, and other outlets, detailing the platform's scale (1,800+ subscribers, ~15,000 monthly campaigns, victims in 30-35 countries).

Sources cited for Kratos Phishing-as-a-Service Platform Dismantled in

Threats related to Kratos Phishing-as-a-Service Platform Dismantled in

Detection coverage for TL-2026-1613

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1613 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1613

4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats