Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit — Threadlinqs Intelligence
As of 2026-07-22, Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit is a medium-severity campaign threat attributed to Kratos PhaaS Operator (alleged developer, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1613 · Severity: MEDIUM · Status: MITIGATED · Category: CAMPAIGN
Attribution: Kratos PhaaS Operator (alleged developer · FINANCIAL
German (BKA/ZIT Frankfurt), US, and Indonesian law enforcement dismantled Kratos, a Node.js-based AiTM (adversary-in-the-middle) phishing-as-a-service platform sold via a website and Telegram shop
Kratos is a Phishing-as-a-Service (PhaaS) platform, active since at least September 2025 (with kit-lineage tracing back further under aliases SneakyLog/Sneaky 2FA), that industrialized adversary-in-the-middle (AiTM) credential and session theft against Microsoft 365 accounts. Operators purchased subscription access via a dedicated website and a Telegram-based shop, then used a central operator dashboard to configure and launch campaigns without needing to write or host any phishing code themselves — 'even low-skill actors could point a working AiTM kit at a target,' per reporting.
The kit offered operators a choice of two delivery modes from its 'Deploy' subdomain: a simpler PHP-based static Office 365 credential-harvesting page, or a Node.js reverse-proxy server that relays the victim's real-time login transaction to Microsoft's actual authentication endpoints (login.live.com / microsoftonline.com) while transparently capturing the resulting authenticated session cookie. Because the proxy relays a genuine Microsoft authentication flow, any MFA challenge the victim completes is satisfied against the real Microsoft service — the operator never needs to defeat MFA directly, only to capture the session cookie issued at the end of the transaction. That cookie alone is sufficient to assume the victim's authenticated session (T1550.004 Use Alternate Authentication Material: Web Session Cookie), which survives password resets and requires explicit session/token revocation to remediate.
Lures were highly varied and multi-staged: phishing emails impersonated document-sharing and productivity notifications ('User N has shared a document with you', 'Sign the document via DocuSign', 'An invoice has been sent', 'Notice of charge - [6-digit number]'), often routed victims through trusted intermediary platforms (SharePoint, OneDrive, Canva, Tilda, Microsoft Forms) before redirecting to the actual phishing page, and used six distinct payload delivery mechanisms: direct links, personalized QR codes (including QR codes embedded in fake W-2 tax documents in a February 10 campaign targeting ~100 US manufacturing/retail/healthcare organizations), weaponized HTML/SVG attachments, ICS calendar invites, RFC-compliant EML files, and PDF/DOCX documents with embedded QR codes. Adobe Creative Cloud/Document Cloud invoice-urgency lures were also used as a secondary brand alongside the primary Microsoft 365 theme.
The kit built in substantial anti-analysis and anti-bot tradecraft: CAPTCHA gating (Cloudflare Turnstile, reCAPTCHA, hCaptcha) to filter sandboxes and automated scanners before serving the real phishing payload; an animated 'Loading in progress…' envelope overlay on a blurred fake document as a visual fingerprint/stall; three-attempt password-entry limiting before redirecting away; geographic/device-type victim filtering via geoplugin.net and VPN/proxy detection; obfuscated JavaScript (a 'V2' generation of the kit); and dynamic domain generation across low-cost TLDs (.horse, .cfd, .sbs, .online) plus abuse of compromised legitimate WordPress sites (observed German .de and Spanish .es domains) and Cloudflare-fronted infrastructure to mask origin hosting. Backend hosting spanned Azure, Google Cloud, and the bulletproof/VPS provider Host4Geeks. Stolen data was exfiltrated to operators via Telegram bot API (api.telegram.org) — blending exfiltration traffic with legitimate encrypted Telegram traffic to evade DPI — or delivered as JSON via email; the operator panel itself was protected by a master password plus Telegram-based 2FA. The architecture was described as 'decoupled,' separating the victim-facing phishing front end from backend credential storage so harvested data remained accessible even after individual phishing URLs were taken down.
Security researchers identified a durable, high-confidence detection signature: Kratos login pages consistently load a paired pair of static assets, barr.svg and lg.svg, and POST stolen credentials to predic
Target sectors: manufacturing, retail, health, industrial, legal, education, government administration, finance
Target regions: united states of america, germany, spain, 039 - Southern Europe, Europe
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CAMPAIGN, MEDIUM, threat intelligence, cybersecurity, T1583, T1584, T1587, T1588, T1566, T1566, T1566, T1199, T1557, T1539