An international police operation has dismantled Kratos, a large-scale phishing-as-a-service platform. Massively exploited by cybercriminals, it made it possible to bypass double authentication. The offensive called “Olympus Blade” made it possible to neutralize more than 200 servers and arrest the alleged mastermind of the criminal service.
German police announce they have dismantled the central infrastructure of Kratosone of the most widespread phishing platforms in the world. First spotted in early January 2026 by researchers at KnowBe4 Threat Labs, the phishing-as-a-Service (PhaaS) kit has greatly contributed to the democratization of scams and cyberattacks.
The kit is described as a real machine for collecting identifiers through fake web pages. At the time of its discovery, KnowBe4 Threat Labs estimated that more than 90% of credential compromises could be based on ready-made platforms like Kratos by the end of the year. Faced with the threat, the authorities redoubled their efforts to put an end to Kratos’ activities.
Also read: A direct debit of €69 will soon be made? Do not click on this button.
More than 1800 pirates used Kratos to trap you
The authorities estimate that more than 1,800 criminals have purchased access to the platform. Every month, they deployed around 15,000 phishing campaigns around the world. Thanks to the scams deployed with Kratos, cybercriminals were able to amass a fortune. At the same time, the individuals behind the kit have been able to raise more than 300,000 euros since 2024. The subscription was mainly paid in cryptocurrencies.
The German Federal Criminal Police Office (BKA) was able to identify 850 victims from 35 different countries, mainly in Europe and the United States. Taking into account all the campaigns carried out, the authorities estimate that Kratos has caused several hundred thousand victims. It is “one of the most widely used criminal phishing services in the world”estimate the BKA.
A kit capable of bypassing double authentication
The phishing kit allowed its users to launch two attack modes. The first mode of attack simply recovered the victim’s identifiers. With Kratos, hackers have notably developed fake Microsoft authentication pages, designed to siphon passwords and identifiers.
The alternative proposed by Kratos made it possible to bypass two-factor authentication by directly stealing session cookies. This is a small temporary file placed by the site in the browser to remember the identity of an Internet user throughout their navigation. It embeds a unique identifier through which the site server immediately knows that this device has already connected successfully, without needing to check everything again. This file automatically disappears as soon as the user logs out, closes their browser, or when the server decides to end the session.
Thanks to these, the targeted system did not require no multi-factor authentication code. He was convinced that he was dealing with the Internet user who held the account, and did not initiate double authentication. Many phishing tools, like Evilginx, also rely on cookies to make multi-factor authentication completely useless.
Also read: A pirate host was dismantled – 250 servers used by cybercriminals were seized
Kratos developer arrested
The police operation, carried out by the Frankfurt public prosecutor’s office with the help of the American authorities, made it possible to neutralize more than 200 servers. The kit’s infrastructure was thus dismantled, and all the services offered by Kratos became inoperable. The official website of the tool has been seized. It now displays a typing bannerstamped with the logo of the FBI and the authorities involved. The offensive, dubbed “Olympus Blade,” did not stop there. At the request of German law enforcement, Indonesian authorities arrested the alleged developer and technical administrator of the platform in Indonesia.
👉🏻 Follow tech news in real time: add 01net to your sources on Google, and subscribe to our WhatsApp channel.
Source :
German police
