LIVE · cybersecurity feed
Live wire
phishing

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]

zeroday.news · 10d ago

Law enforcement agencies in Germany and the United States have dismantled the Kratos phishing-as-a-service (PhaaS) platform and arrested its developer in Indonesia. The operation, dubbed "Operation Olympus Blade," involved the seizure of over 200 servers, effectively rendering the malicious service inoperable.

The Frankfurt Prosecutor General's Office (ZIT) and Germany's Federal Police (BKA) led the international effort, collaborating with U.S. law enforcement. The BKA characterized Kratos as one of the most widely used criminal phishing services globally, with confirmed victims across 35 countries, particularly within Europe and the United States.

Authorities estimate that more than 1,800 criminal customers purchased access to Kratos, using it to launch approximately 15,000 phishing campaigns each month. These campaigns had the potential to affect thousands of recipients worldwide. The phishing toolkit allowed threat actors to create and manage convincing fake Microsoft authentication pages designed to steal email addresses and passwords.

Once compromised, these Microsoft accounts were frequently leveraged for further criminal activities, including business email compromise (BEC), data theft, account takeover, and additional phishing attacks targeting the victims' contacts.

The service's owner is believed to have generated at least 300,000 Euros (approximately $342,000 USD) in subscription fees since 2024. With the arrest of the technical administrator and the shutdown of critical infrastructure, authorities anticipate a halt to these ongoing phishing campaigns.

A seizure banner has been placed on the service's website, announcing the law enforcement action and indicating that domain ownership has been transferred to the FBI. The seized servers are expected to provide new forensic evidence, which may aid in identifying additional customers of the Kratos service.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]