CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ✉ Email Security Aug 12, 2026

Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI - www.trendmicro.com

www.trendmicro.com Archived Aug 12, 2026 ✓ Full text saved

Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI www.trendmicro.com

Full text archived locally
✦ AI Summary · Claude Sonnet


    Cyber Crime Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI™ Kratos, the phishing-as-a-Service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline by the BKA and ZIT in an operation dubbed Olympus Blade. By: Christopher Boyton, Stephen Hilt Jul 22, 2026 Read time: 3 min (760 words) Kratos, the phishing-as-a-service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline by the BKA and ZIT (working with US authorities) in an operation dubbed Olympus Blade. The developer and technical administrator was arrested in Indonesia. This platform evolved from Sneaky2FA, a phishing kit targeting Microsoft accounts since October 2024. Over 1,800 criminal subscribers had rented access to Kratos and used it to run an estimated 15,000 phishing campaigns a month. More than 200 servers were shut down, and victims across more than 30 countries, concentrated in Europe and the United States, add up to hundreds of thousands since late 2024. TrendAI™ supported the investigation by providing threat intelligence, infrastructure fingerprinting, victimology, and analysis of the actors behind Kratos. This information was provided to the BKA starting in 2025. The subscription model made Kratos scalable: affiliates could rent the kit and rely on the service to support phishing operations. That is why this takedown matters beyond one arrest: it disrupted the infrastructure and business model that enabled lower-skill operators to run high-volume credential theft campaigns. On July 20, 2026, Germany's Bundeskriminalamt (BKA) and the Frankfurt-based Central Office for Combating Internet Crime (ZIT), working with US authorities, took down the central infrastructure behind Kratos, a phishing-as-a-service (PhaaS) platform used to steal Microsoft 365 credentials at scale. Indonesian authorities also arrested the developer and technical administrator of the service. More than 200 servers were shut down, and the platform’s infrastructure was taken fully offline. Over 1,800 criminal subscribers had purchased access to Kratos and used it to run an estimated 15,000 phishing campaigns a month, each capable of reaching thousands of recipients. Victims spanned across more than 30 countries (concentrated in Europe and the United States), and the total number of victims since late 2024 runs into the hundreds of thousands. BKA and ZIT stated the group had earned more than €300,000 (approximately 342,000 USD) since 2024. Figure 1. Seizure banner displayed on former Kratos infrastructure, as part of the joint FBI/BKA/ZIT action (Operation Olympus Blade). Kratos is not a new kit. It is the direct evolution of Sneaky2FA, an adversary-in-the-middle (AiTM) phishing kit that has targeted Microsoft 365 accounts since October 2024. Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through, which is what let the kit defeat MFA rather than just harvest a password. Sold through a Telegram-based subscription model, the kit gave affiliates a ready-made service: this included phishing domains and antibot checks (Cloudflare Turnstile among them). In November 2025, browser-in-the-browser (BitB) login windows were added that were convincing enough to fool users who had been trained to check the address bar. That business model, renting the kit and letting someone else run the campaign, is what allowed low-skill operators to reach the volume the BKA and ZIT described this week. TrendAI™ has tracked Sneaky2FA and its evolution into Kratos since December 2024 and has shared intelligence with the BKA since 2025. Over that period, we provided methodologies for fingerprinting Kratos infrastructure and identifying phishing panels, along with observed victimology and regular infrastructure updates. In March 2025, we observed a Telegram channel advertising the Kratos phishing-as-a –Service offering. Further investigation found that Kratos was likely a rebrand of Sneaky2FA. We conducted an in-depth investigation into the operators and associates and shared our findings with the BKA to support its investigation. This is the same model of cooperation that supported the March 2026 disruption of Tycoon 2FA, where threat intelligence gathered through ongoing monitoring was provided to Europol ahead of that action. Sustained tracking of a kit's infrastructure and its generational changes over time is what makes it possible to hand law enforcement something they can act on, rather than a single snapshot. Taking a platform with this footprint offline in a single coordinated action, including the arrest of its developer, is a meaningful result. Carsten Meywirth, BKA’s cybercrime division head, called it a pioneering effort and a clear signal to other cyber actors. We agree with that assessment and congratulate the BKA and its partners. As with many other cybercrime disruptions, the strongest outcomes come from cooperation between law enforcement and the private security industry. TrendAI™ is proud to be a long-standing and active member of that community, helping make the world safer for the exchange of digital information. Tags Cyber Crime | Research | Articles, News, Reports | Cyber Threats Authors Christopher Boyton Adversary Hunter Stephen Hilt Senior Threat Researcher CONTACT US Related Articles A Secure Access Service Edge (SASE) Guide for Leaders Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave See all articles
    💬 Team Notes
    Article Info
    Source
    www.trendmicro.com
    Category
    ✉ Email Security
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗