The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape.
As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments.
Despite being disrupted under Operation Olympus Blade, which led to the seizure of more than 200 servers and the arrest of its lead developer in Indonesia, Kratos has effectively transitioned from an active service into a reusable blueprint for adversaries.
Kratos was a highly sophisticated PhaaS ecosystem designed to industrialize credential theft and enable large-scale account takeover operations.
Built specifically for Microsoft 365 targeting, the platform leveraged adversary-in-the-middle (AiTM) techniques to intercept live authentication sessions, allowing attackers to capture not only credentials but also session tokens capable of bypassing multi-factor authentication (MFA).
Its infrastructure overlapped with other major AiTM kits such as Tycoon, Flowerstorm, Sneaky2FA, and EvilProxy, indicating a shared backend ecosystem increasingly favored by cybercriminal groups.
At its peak, Kratos supported over 1,800 subscribers who collectively launched approximately 15,000 phishing campaigns per month.
The platform’s decoupled architecture ensured resilience, with stolen data exfiltrated in real time to Telegram bots via encrypted channels.
This design allowed attackers to retain access to harvested credentials even if phishing domains were rapidly taken offline.
Technical analysis conducted by ANY.RUN researchers revealed distinct fingerprinting artifacts associated with the kit, including the presence of barr.svg and lg.svg files, which provide near-perfect attribution of Kratos-related activity.
These identifiers are now being used by defenders to track derivative campaigns that continue to reuse the original kit’s components.
Dismantled Kratos Phishing Kit
Kratos evolved significantly from earlier kits such as Sneaky2FA, transitioning from simple credential harvesting toward full-session hijacking.
Its multi-generation development, tracked across versions V0 through V2, introduced increasingly obfuscated code and improved brand impersonation templates, including lures mimicking Adobe Creative Cloud and DocuSign workflows.

The service also implemented automated victim filtering via geolocation APIs and integrated anti-analysis mechanisms such as CAPTCHA systems and Cloudflare Turnstile to evade detection by security tools.
The attack chain typically begins with phishing emails routed through trusted intermediary services such as SharePoint, OneDrive, or Microsoft Forms, allowing campaigns to bypass email security gateways.
Victims are then funneled through verification gates before landing on highly convincing phishing pages that simulate legitimate Microsoft authentication flows.
During login attempts, the platform relays authentication data in real time, often using WebSocket communication indicative of AiTM behavior, while exfiltrating credentials to Telegram-controlled infrastructure.

The implications for enterprises are severe. By capturing session tokens, attackers can maintain persistent access even after password resets, unless sessions are explicitly revoked.
This enables advanced business email compromise (BEC) scenarios, lateral movement across cloud services such as Teams and SharePoint, and supply chain targeting through compromised communication channels.
Real-time IOC feeds further support proactive defense by allowing organizations to block malicious domains and infrastructure before compromise occurs.
Although Operation Olympus Blade disrupted the core service, the rapid emergence of alternatives such as Kali365 underscores a persistent reality: PhaaS platforms are evolving faster than enforcement actions can contain them.
As Microsoft 365 remains a central pillar of enterprise operations, attackers continue to exploit its authentication workflows, shifting the battleground from vulnerability exploitation to identity compromise at scale.
What Features Should AI SOC Have in 2026? A Complete Checklist : Download the AI SOC Features Checklist

