Last seven days
- First activity
- Aug 4, 2026
- Last activity
- Aug 4, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
MITRE ATT&CK
Reporting
German authorities, working with the United States and Indonesia, dismantled the core infrastructure of Kratos, a phishing-as-a-service platform described as one of the world’s most widely used criminal phishing services. Investigators seized or neutralized more than 200 servers and arrested the alleged developer and technical administrator in Indonesia, a move authorities said rendered the service inoperable. The action was carried out under Operation Olympus Blade, and the FBI took control of Kratos-linked domains to support follow-on investigation and customer identification. Kratos supplied Microsoft-themed phishing pages designed to steal credentials and session cookies, allowing attackers to hijack accounts and bypass multi-factor authentication. Authorities said the platform was used by roughly 1,800 criminal customers to launch about 15,000 phishing campaigns per month against victims in at least 35 countries, with organizations in the United States and Europe—particularly in manufacturing, retail, healthcare, and education—among the main targets. Investigators estimate the operation generated more than €300,000 since 2024.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.