5 min read By Excello Mail Team

Operation Olympus Blade Took Down Kratos. 1,800 Customers Ran 15,000 Phishing Campaigns a Month With It.

German and US authorities dismantled the Kratos phishing-as-a-service platform this week, seizing over 200 servers and arresting its developer in Indonesia. Here is what the takedown of one of the world's largest session-hijacking phishing kits reveals about the criminal economy that email authentication is built to disrupt.

Germany’s Federal Criminal Police Office and the Frankfurt public prosecutor’s cybercrime unit, working alongside the FBI’s Dallas Field Office and the US Attorney’s Office for the Northern District of Texas, announced this week that they had pulled the plug on Kratos, described by the investigating officers as one of the most widely used criminal phishing kits in the world. The operation, code-named Olympus Blade, seized more than 200 servers, transferred the platform’s domain to FBI control, and ended with the arrest of Kratos’s alleged developer and technical administrator in Indonesia.

The numbers behind the takedown are worth sitting with. Investigators estimate that roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month, generating hundreds of thousands of victims across more than 30 countries, concentrated in Europe and the United States, since late 2024. The operators are believed to have earned at least 300,000 euros from subscription fees alone.

A Subscription Business, Not a Single Attacker

What made Kratos dangerous was not novelty. It was accessibility. Customers signed up through a dedicated website and a Telegram shop, paid in cryptocurrency, and got a working phishing kit with no coding skill required. That is the phishing-as-a-service model in its purest form: a small operating team builds and maintains the infrastructure, and thousands of independent criminals rent access to run their own campaigns against whatever targets they choose.

Kratos gave those customers two modes to work with. The simpler option was a plain PHP page that just harvested whatever username and password a victim typed in. The more dangerous option was a Node.js reverse proxy built to sit between the victim and the real Microsoft login page, relaying the authentication exchange in real time. That second mode is what is known as adversary-in-the-middle, or AiTM, phishing. It does not just steal a password. It steals the session cookie that Microsoft 365 issues after a successful login, including one completed with multi-factor authentication. Whoever holds that cookie can walk into the account without ever needing the second factor at all.

Why Removing One Supplier Does Not Remove the Demand

It is tempting to read a takedown of this size as a win with a clean edge. It is a real win, and 200 fewer servers running active phishing infrastructure is 200 fewer platforms available today. But 1,800 paying customers were not customers of Kratos specifically. They were customers of session-cookie theft as a service, and Kratos happened to be the vendor they used this year. AiTM kits with a similar architecture, real-time credential relay, session cookie capture, MFA walked around entirely, have shown up under other names before and will show up under other names again. Taking one supplier off the market does not make the buyers disappear.

That is the part of this story that matters most for anyone running a domain, not just security teams tracking phishing-as-a-service infrastructure. Every one of those 15,000 monthly campaigns still had to start the same way every phishing campaign starts: an email that looked enough like something legitimate that a recipient opened it and clicked through to a Microsoft-branded login page. AiTM defeats multi-factor authentication after the click. Email authentication is what determines how many of those emails were ever positioned to get a click in the first place.

What Domain Owners Should Do

Get your own domain to DMARC enforcement, p=reject, not just a published record. A Kratos-style operator who cannot spoof your domain directly has to fall back on lookalike domains or compromised third-party accounts, both of which are harder to scale to 15,000 campaigns a month and easier for recipients and filters to catch.

Treat session cookies as credentials, because AiTM kits already do. A password reset after a phishing report is not enough if the session token issued before the reset is still valid. Conditional access policies that re-evaluate sign-in risk and shorten session lifetimes reduce how much a stolen cookie is worth.

Watch for Microsoft-branded login pages specifically in your phishing simulation and awareness training. Kratos targeted Microsoft 365 because it is the identity provider behind the largest number of business inboxes on earth. That concentration is not going away just because one vendor did.

Read your DMARC aggregate reports for anomalies in the weeks after a major takedown like this one. Displaced criminal operators do not stop operating, they migrate platforms, and a domain that has never seen a given spoofing pattern before can suddenly see one as customers of a shuttered kit look for a new home.

The Takeaway

Operation Olympus Blade is a genuine disruption of real criminal infrastructure, and the agencies involved deserve credit for building a case that reached from a Frankfurt prosecutor’s office to an arrest in Indonesia. It does not, however, change the underlying economics that made Kratos profitable in the first place: multi-factor authentication alone no longer stops account takeover once a session cookie is in an attacker’s hands, and the email that delivers the first click is still the cheapest, most scalable part of the entire attack chain for whoever builds the next kit. Enforced email authentication is what keeps that first click from ever landing in your organization’s inboxes.


Excello Mail helps you move your domain from a published DMARC record to real p=reject enforcement, closing the spoofing vector that phishing-as-a-service platforms depend on to reach your employees and customers. Sign up for free to Excello Mail and see exactly where your domain stands today.