Operation Olympus Blade: The Takedown of Kratos
On July 21, 2026, the digital underworld lost one of its most potent tools. German and U.S. authorities didn’t just disrupt a phishing service—they dismantled an entire criminal enterprise built on the illusion of legitimacy. Kratos, a phishing-as-a-service platform, had been quietly feeding a global machine: 1,800 criminal customers, 15,000 phishing campaigns every month, and victims spanning 35 countries. The operation, codenamed Olympus Blade, wasn’t a raid. It was an autopsy.
The Frankfurt ZIT and Germany’s Federal Criminal Police Office (BKA), working alongside U.S. agencies, didn’t just seize servers. They seized the entire architecture of trust. More than 200 machines, each humming with fake Microsoft login pages, were pulled offline. The developer? Arrested in Indonesia. The domain? Redirected to the FBI. A seizure banner now sits where Kratos once lived—a digital tombstone.
This wasn’t a one-off. It was the culmination of years of coordinated intelligence. Kratos didn’t just steal passwords. It harvested session tokens, bypassed MFA, and turned compromised accounts into launchpads for business email compromise, data theft, and social engineering campaigns targeting victims’ own contacts. The platform’s owner? Earned over €300,000 since 2024. Not from ransomware. Not from selling stolen data. But from subscriptions.
That’s the real horror. Kratos wasn’t a tool. It was a SaaS product. And people paid for it.
The BKA called it "one of the world’s most widely used criminal phishing services." That’s not hyperbole. It’s a market share report.
How Kratos Worked: The Illusion of Microsoft
Kratos didn’t need zero-days. It didn’t need advanced malware. It just needed a convincing login page.
Its phishing kits replicated Microsoft’s authentication portal with eerie precision. The logo. The color scheme. The subtle loading animation. To the average user, it looked real. Even the URL looked plausible—subdomains mimicking Microsoft’s domain structure, hosted on legitimate cloud infrastructure.
Once a victim entered their credentials, Kratos didn’t just steal them. It captured the subsequent authentication tokens—those ephemeral keys that let you stay logged in across devices. That’s how it bypassed MFA. The attacker didn’t need the code sent to your phone. They hijacked the session after the fact.
And then? They didn’t stop.
The platform gave customers tools to monitor inboxes, create forwarding rules, and send fraudulent invoices. One compromised account could become a pipeline for millions in BEC fraud. The criminal didn’t need to be technical. They just needed a credit card.
This wasn’t a script kiddie’s playground. It was a corporate-grade fraud factory.
The Legal Aftermath: Forensics Over Firepower
The arrest of the developer was symbolic. The real victory was in the servers.
By seizing the infrastructure, investigators didn’t just shut down a service—they opened a forensic treasure trove. Every login attempt. Every IP address. Every session token. Every customer ID. All of it was preserved.
This is where the operation gets truly chilling. The BKA didn’t just say, "We took them down." They said, "We know who you are." The seized servers contained a complete customer list. Hundreds of thousands of potential targets. And now, law enforcement has the evidence to trace every single one.
The FBI’s seizure banner wasn’t just a message to criminals. It was a warning to the entire ecosystem: your infrastructure is not safe. Your anonymity is a myth.
This was the first time German and U.S. agencies had jointly dismantled a PhaaS platform at this scale. But it wasn’t the first time they’d done it.
The PhaaS Market: Kratos Wasn’t Alone
Kratos didn’t emerge in a vacuum. It was the latest in a line of increasingly sophisticated phishing-as-a-service platforms.
Just three months earlier, in April 2026, the FBI and Indonesian authorities took down W3LL—a PhaaS platform that sold for $500 and enabled session-token interception to bypass MFA. The FBI’s Special Agent in Charge called it "a full-service cybercrime platform." That phrase stuck. Because it’s true.
Then, in July 2026, just weeks before Kratos fell, a new player emerged: Forg365. It combined adversary-in-the-middle (AiTM) phishing with AI-generated lures. The same AI that helps marketers write better emails now helps criminals write better scams.
"AI reduces the cost of developing custom phishing content," said ZeroBEC, "but it also reduces the cost of building custom PhaaS platforms."
That’s the new normal. The barrier to entry has collapsed. You don’t need to be a coder. You don’t need to understand OAuth. You just need to click a button.
And the market? It’s crowded. Kali365. Sneaky2FA. Tycoon2FA. RaccoonO365. Each one a variation on the same theme: steal credentials, bypass MFA, monetize access.
Kratos wasn’t the worst. It was just the biggest.
Securing Against the AI-Powered Phishing Tide
So what do you do?
First, disable device-code authentication in Microsoft Entra ID unless you absolutely need it. It’s a legitimate OAuth flow—but it’s also a backdoor for attackers.
Second, monitor your Entra logs for device-code authentication events. If you see a user logging in from a device you’ve never seen before, and it’s using device-code? That’s a red flag.
Third, audit OAuth grants. Who has access to your Microsoft 365 apps? When was the last time you reviewed those permissions?
And finally, revoke tokens. Promptly. If you suspect a compromise, don’t wait for the next audit cycle. Revoke all active sessions. Force a re-authentication.
This isn’t about blocking every attack. It’s about making the cost of failure too high.
Kratos is gone. But the infrastructure it relied on? Still there. The attackers? Still out there. And the AI that powered their lures? Still learning.
The only thing that’s changed is this: we now know we can take them down.
And that’s a start.