Authorities have successfully dismantled Kratos, a sophisticated phishing-as-a-service (PhaaS) platform designed to steal Microsoft 365 credentials on a massive scale. This operation, known as Operation Olympus Blade, targeted the infrastructure that enabled cybercriminals to launch approximately 15,000 phishing campaigns each month, affecting organizations worldwide.
Kratos evolved from the Sneaky2FA kit, offering affiliates ready-made login pages, hosting solutions, and advanced evasion techniques that made fraudulent sign-ins more challenging to detect. The service operated by sending phishing emails that directed victims through legitimate-looking services before presenting a counterfeit Microsoft 365 login page. This method allowed Kratos to intercept both passwords and active session tokens, effectively bypassing multi-factor authentication (MFA) protections.
Analysts at ANY.RUN identified Kratos as a mature PhaaS platform, complete with a user-friendly dashboard, anti-bot measures, and automated delivery of stolen credentials to attackers. The service significantly lowered the technical barriers for cybercriminals, enabling them to execute convincing Microsoft 365 credential theft campaigns with minimal expertise.
Despite the successful takedown of Kratos, the threat landscape remains concerning. The platform had reportedly supported over 1,800 subscribers, facilitating a vast number of phishing campaigns. The techniques employed by Kratos have set a precedent, serving as a blueprint for other malicious actors to develop similar phishing kits targeting Microsoft 365 users.
Kratos Phishing Tactics and Implications
Kratos was engineered as a reusable criminal toolkit rather than a one-off campaign. Its affiliates could mimic familiar services such as document-sharing and creative-software platforms, sending emails that routed victims through SharePoint, OneDrive, Microsoft Forms, Canva, or other legitimate web services before reaching the final phishing page. This layered delivery model helped criminals evade email filters, as the initial link did not always appear to point to a phishing site.
Before displaying a fake Microsoft sign-in form, Kratos could present a CAPTCHA or browser check to screen out automated scanners. Victims would then see a blurred document or invoice with a loading animation, followed by a convincing authentication request designed to create urgency and trust. When users entered their credentials and completed MFA, the kit relayed the live session and collected the authentication token. This allowed attackers to access the account as an already verified user, meaning a password reset alone might not end the intrusion if active sessions and refresh tokens remained valid.
The impact of such attacks can extend well beyond a single mailbox. Attackers with Microsoft 365 access may read business conversations, change payment instructions, steal files from SharePoint, Teams, and OneDrive, or use a trusted account to send new phishing messages to colleagues, customers, and suppliers.
Defending Against Phishing Attacks
Organizations should treat unexpected document-sharing notices and login prompts as high-risk, especially when they arrive through email, chat, or links from unfamiliar websites. Users are advised to access Microsoft 365 directly rather than signing in through unsolicited links, and security teams should verify suspicious messages before employees interact with them.
Defenders should monitor sign-in records for unusual locations, rapid logins from distant places, unfamiliar devices, and signs of token replay. Monitoring mailbox rules is also crucial, as compromised accounts can be used to quietly redirect financial messages or hide security alerts. Password resets should be paired with the revocation of active sessions and refresh tokens after a suspected account takeover. Security teams should also apply conditional-access controls and use phishing-resistant authentication methods where possible.
The dismantling of Kratos marks a significant victory in the fight against cybercrime. However, the persistence of similar threats underscores the need for continuous vigilance and proactive security measures. Organizations must remain alert to evolving phishing tactics and invest in comprehensive security strategies to protect their digital assets and sensitive information.