Кибербезопасность3 мин. чтения

Authorities Dismantle Kratos Phishing Platform and Arrest Developer

German and U.S. law enforcement dismantled the Kratos phishing platform's infrastructure and arrested its developer in Indonesia. The service facilitated 15,000 monthly attacks primarily against Microsoft accounts.

Authorities Dismantle Kratos Phishing Platform and Arrest Developer
Police arresting a cybercriminal in a dark office with computer equipment.

The Kratos phishing platform, one of the world's largest phishing-as-a-service (PhaaS) operations, was dismantled in a joint operation by German and U.S. authorities. The platform's developer was arrested in Indonesia, with over 200 servers seized. Kratos was used for 15,000 monthly phishing attacks, primarily targeting Microsoft users across 35 countries.

Key Takeaways

  • German and U.S. authorities dismantled the Kratos phishing platform on May 12, 2024.
  • Over 200 servers were seized, rendering the platform inoperable.
  • The developer was arrested in Indonesia; identity remains undisclosed.
  • Kratos facilitated 15,000 monthly phishing attacks across 35 countries.
  • The developer earned at least €300,000 since early 2024.
  • Primary attack targets were Microsoft account credentials.
Operation to dismantle the Kratos phishing platform

How the Kratos Platform Operated

Kratos provided cybercriminals with tools to create counterfeit Microsoft login pages. The subscription-based service offered turnkey phishing solutions.

Technical Features

  • Pre-made Microsoft 365 phishing page templates
  • Automated stolen credential collection system
  • Dashboard for monitoring successful attacks
  • Multilingual phishing campaign support

Scope and Impact

According to Germany's BKA, Kratos had over 1,800 criminal clients conducting approximately 15,000 monthly phishing attacks. Each campaign could potentially target thousands of users worldwide.

Metric Value
Servers seized 200+
Countries affected 35
Monthly revenue €300,000+
Active clients 1,800+

How to Protect Against Phishing Attacks

While Kratos is dismantled, phishing threats remain. Key protective measures:

  1. Always verify URLs before entering credentials
  2. Enable two-factor authentication for critical services
  3. Train employees to recognize phishing emails
  4. Install anti-phishing browser extensions
  5. Regularly update passwords for high-value accounts

Questions & Answers

Which countries participated in dismantling Kratos?

Primary participants were Germany (BKA and Frankfurt Prosecutor's Office) and the U.S. (FBI). The developer's arrest occurred in Indonesia through international cooperation.

How much money did the Kratos developer make?

Authorities estimate the developer earned at least €300,000 from platform subscriptions since early 2024.

How did the Kratos phishing platform operate?

Kratos provided cybercriminals with tools to create fake Microsoft login pages through a subscription-based service offering turnkey phishing solutions.

What consequences will Kratos users face?

Authorities accessed Kratos servers and may identify platform clients. Service users face potential criminal prosecution.

How can I protect against similar phishing attacks?

Use two-factor authentication, verify website URLs, and avoid clicking suspicious email links.

Will there be more Kratos-related arrests?

The investigation continues as authorities analyze seized server data. Additional client arrests are possible.