TempMail Ninja
//

Kratos Phishing Kit Dismantled by International Law Enforcement

8 min read
TempMail Ninja
Kratos Phishing Kit Dismantled by International Law Enforcement

In a coordinated international operation dubbed Operation Olympus Blade, global law enforcement authorities have successfully dismantled the core infrastructure powering the notorious Kratos phishing kit, one of the cybercriminal underground’s most prolific Phishing-as-a-Service (PhaaS) platforms. The joint action, led by Germany’s Central Office for Combating Internet Crime (ZIT) and Federal Criminal Police Office (BKA) alongside the U.S. Federal Bureau of Investigation (FBI) and the U.S. Attorney’s Office for the Northern District of Texas, resulted in the seizure of over 200 servers worldwide and the domain takeover of the platform’s central infrastructure. Simultaneously, Indonesian law enforcement officers arrested the service’s primary developer and technical administrator in Indonesia, severing the nerve center of a network that enabled thousands of threat actors to bypass legacy multi-factor authentication (MFA) protocols at scale.

Tracked extensively by Microsoft Threat Intelligence under the moniker SneakyLog (and previously associated with the Sneaky 2FA family), the platform functioned as an industrialized, franchise-style cybercrime engine. Investigators estimate that Kratos supplied more than 1,800 criminal “franchisees” who deployed approximately 15,000 specialized phishing campaigns every month against Microsoft 365 environments across more than 35 countries. Generating over €300,000 ($342,000) in illicit subscription revenues since early 2024, the platform democratized advanced credential harvesting, allowing low-skilled threat actors to execute sophisticated Adversary-in-the-Middle (AiTM) session hijacking attacks against enterprise targets. The takedown underscores a critical turning point in global law enforcement’s approach to cloud-native cybercrime while exposing the structural weaknesses inherent in standard two-factor authentication (2FA) mechanisms.

Operation Olympus Blade: Dismantling the Infrastructure Behind the Kratos Phishing Kit

The downfall of the Kratos phishing kit marks one of the most significant disruption efforts against commercialized cybercrime infrastructure in 2026. Operating as a turn-key PhaaS platform, Kratos provided subscribers with automated deployment dashboards, real-time victim management consoles, and decentralized exfiltration pipelines. Customers gained access to the platform by purchasing subscriptions through a dedicated web portal and an automated Telegram shop, paying via privacy-focused cryptocurrencies. The business model mirrored modern software-as-a-service (SaaS) enterprises, offering technical support, regular feature updates, and evasion patches to maintain operational resilience against security scanners.

The scale of the operation was vast. The platform’s infrastructure was distributed across dozens of hosting providers across Europe and North America to ensure redundancy and withstand abuse complaints. According to official statements from the BKA and ZIT, each individual campaign orchestrated through Kratos had the potential to compromise thousands of corporate users in sectors including manufacturing, healthcare, financial services, and retail.

  • Infrastructure Rendered Inoperable: Over 200 specialized proxy and C2 servers seized across multiple jurisdictions under federal search warrants.
  • Global Reach: Confirmed victim organizations across 35 countries, heavily concentrated across the United States and European Union member states.
  • Franchise Operational Model: Enabled 1,800+ criminal customers to launch over 15,000 monthly phishing campaigns targeting Microsoft enterprise accounts.
  • Central Operator Arrested: Indonesian national police apprehended the head developer and infrastructure administrator in a synchronized strike.

Upon taking control of the platform’s primary C2 domains, federal authorities deployed law enforcement seizure banners detailing the international collaboration. The disruption not only disabled active phishing pages across thousands of compromised subdomains but also cut off criminal access to stored victim logs, preventing post-compromise activity such as Business Email Compromise (BEC), internal spear-phishing, and corporate data exfiltration.

Deconstructing the Kratos Phishing Kit: Dual-Engine Architecture and AiTM Proxying

What set the Kratos phishing kit apart from generic credential harvesters was its sophisticated technical design. Threat intelligence analysts from cybersecurity firms including ANY.RUN, KnowBe4 Threat Labs, and Sekoia revealed that Kratos utilized a dual-engine architecture, offering attackers flexibility depending on their target’s security maturity:

  • Standard Harvesting Mode: A lightweight PHP-based engine designed purely for high-volume credential collection against targets lacking multi-factor authentication controls.
  • Reverse-Proxy AiTM Mode: A highly optimized Node.js reverse-proxy engine designed specifically to bypass modern two-factor authentication in real time.

In its reverse-proxy configuration, Kratos operates as an active intermediary sitting directly between the victim’s browser and the authentic identity provider (such as Microsoft Entra ID / Azure AD). When a victim clicks a malicious link—often disguised as an authentic Microsoft OneDrive, SharePoint, Canva, or Adobe document notification—the Node.js proxy fetches the genuine login portal from Microsoft in real time and renders it to the user. As the victim enters their username and password, the Kratos proxy relays these credentials to Microsoft’s actual servers. When Microsoft requests a 2FA prompt (such as a time-based one-time password [TOTP] from an authenticator app, an SMS code, or a push notification), Kratos forwards the prompt directly to the victim’s screen.

Crucially, once the victim completes the 2FA verification on their legitimate device, Microsoft’s authentication server generates an authenticated session cookie (such as ESTSAUTH or ESTSAUTHPERSISTENT) and transmits it back. Rather than merely recording the password, the Kratos reverse-proxy intercepts this high-value session token from the HTTP response stream before forwarding the payload to the victim. The attacker then injects this stolen session cookie into their own browser, gaining fully authenticated access to the target’s Microsoft 365 environment—bypassing the 2FA prompt entirely, without ever needing to intercept or crack individual MFA codes.

To maximize landing page longevity, Kratos integrated advanced anti-analysis measures. The kit utilized Cloudflare Turnstile human-verification checks to block automated security crawlers, employed obfuscated JavaScript dynamic rendering, and used distinct asset fingerprints (such as paired /assets/img/barr.svg and dsa.svg files) to evade static web reputation filters. Furthermore, exfiltration pipelines were decoupled from the front-end proxy, sending stolen tokens directly to administrative Telegram channels via encrypted API calls to prevent data loss during single-server takedowns.

The Crisis of Legacy 2FA: Why Static Credentials and OTPs Cannot Stop Session Hijacking

The rampant success and rapid proliferation of platforms like the Kratos phishing kit highlight a systemic vulnerability in modern enterprise access management: legacy two-factor authentication is fundamentally unequipped to withstand automated reverse proxies. For years, organizations viewed SMS codes, authenticator app TOTPs, and mobile push prompts as the gold standard of account protection. However, these mechanisms suffer from an architectural flaw—they validate the identity of the user to the proxy server, but they do not validate the identity of the server to the browser.

Because traditional 2FA protocols do not cryptographically bind authentication credentials to the underlying domain origin, an AiTM proxy can seamlessly relay tokens back and forth between the user and the real authentication endpoint. To the identity provider, the traffic appears to originate from an authenticated user completing a standard login sequence. To the user, the login portal is indistinguishable from the real service because it is actively serving live data directly from Microsoft’s servers.

Once an attacker captures an active session token, the security boundaries provided by legacy 2FA collapse. The threat actor obtains immediate, persistent access to cloud mailboxes, enterprise SharePoint drives, sensitive internal communications, and cloud infrastructure. Because the session is already authenticated, subsequent logins during the cookie’s lifetime require no password, no SMS code, and no push approval—leaving automated intrusion detection systems completely blind to the initial breach.

Defending Against AiTM Proxies: FIDO2, WebAuthn, and Continuous Identity Analytics

While law enforcement operations like Operation Olympus Blade temporarily dismantle major PhaaS platforms, cybersecurity experts emphasize that criminal infrastructure adapts quickly. Disruped threat actors frequently migrate to alternative PhaaS offerings such as Tycoon 2FA, Evilproxy, or Muraena. To achieve long-term resilience against AiTM attacks, enterprise security leaders must transition away from legacy authentication models and enforce phishing-resistant 2FA protocols.

The definitive technical defense against reverse-proxy kits lies in standardizing on FIDO2 / WebAuthn protocols, which include hardware security keys (such as YubiKeys) and platform-synced passkeys. Unlike legacy MFA, FIDO2 authentication relies on public-key cryptography and incorporates cryptographic domain binding. During the authentication handshake, the user’s browser automatically injects the verified domain origin (e.g., login.microsoftonline.com) into the cryptographic assertion signed by the security key.

If a victim is lured to a malicious proxy domain managed by a kit like Kratos (e.g., login.microsoft-secure-auth.com), the browser detects that the proxy domain does not match the registered origin stored in the token. The cryptographic signature fails instantly, preventing the proxy from receiving or relaying valid authentication assertions. As a result, AiTM proxies become completely useless, regardless of how convincing the phishing page appears to the human eye.

To build a robust defense-in-depth framework against AiTM session theft, security teams should implement the following strategic steps:

  1. Mandate Phishing-Resistant MFA: Accelerate enterprise-wide deployment of FIDO2 hardware keys and enterprise passkeys across high-value users, administrative personnel, and broad workforce populations.
  2. Eliminate Legacy MFA Fallbacks: Restrict fallback options to legacy authentication methods (such as SMS OTPs or standard TOTPs). An attacker utilizing an AiTM kit will actively force users onto weaker fallback mechanisms if they are permitted by tenant policy.
  3. Deploy Continuous Access Evaluation (CAE): Implement real-time session evaluation frameworks, such as Microsoft Entra CAE. CAE monitors contextual signals—such as sudden IP address switches, geographic anomalies, or device compliance changes—and instantly revokes stolen session cookies mid-stream.
  4. Restrict Device Enrolment and Token Binding: Enforce strict Conditional Access policies requiring compliant, hybrid-joined devices for cloud resource access. Implement token binding protocols to bind session cookies directly to the client device’s TLS connection.
  5. Adopt Behavioral Identity Analytics: Deploy Human Risk Management (HRM) frameworks and identity threat detection and response (ITDR) tools to monitor for impossible travel, unusual user-agent strings, and abnormal post-authentication session behavior.

The dismantling of the Kratos phishing kit demonstrates the power of international law enforcement collaboration in disrupting complex cybercrime supply chains. However, for enterprise security teams, the takedown serves as a clear warning: the era of relying on legacy, password-plus-OTP authentication is over. As PhaaS operators continue to automate AiTM techniques, adopting cryptographically bound, phishing-resistant credentials is no longer an optional upgrade—it is the baseline requirement for modern enterprise cloud security.

TN

Written by

TempMail Ninja

Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.