German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft
German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) (TL-2026-1602), also tracked as Kratos, is a high-severity phishing campaign, first published 2026-07-22. It is attributed to Kratos with medium confidence, affects Microsoft Microsoft 365 / Entra ID authentication, maps to 25 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-1602
- Threat ID
- TL-2026-1602
- Also known as
- Kratos, SneakyLog, Sneaky 2FA, Sneaky Log, Operation Olympus Blade
- Severity
- HIGH
- Status
- MITIGATED
- Category
- PHISHING
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- Kratos
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, retail, health, industrial, legal, education, government administration, finance, technology
- Target regions
- united states of america, Europe, germany, indonesia
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
Malware and tooling: Kratos, Sneaky 2FA, W3LL OV6, SneakyLog_bot, SneakySupport_bot, href.li
German authorities (Frankfurt ZIT, BKA), supported by US law enforcement and Microsoft, dismantled Kratos — also known as SneakyLog and Sneaky 2FA — an adversary-in-the-middle phishing-as-a-service platform that harvested Microsoft 365 credentials and session cookies to bypass MFA. Roughly 1,800 criminal customers ran ~15,000 phishing campaigns per month against victims in 30+ countries; over 200 servers were seized and the alleged developer was arrested in Indonesia.
How German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) works
Kratos is a phishing-as-a-service (PhaaS) kit that evolved from an earlier family of commercial trojans and infostealers into a subscription-based adversary-in-the-middle (AiTM) platform marketed under the names SneakyLog and Sneaky 2FA. Sold via a Telegram bot (@SneakyLog_bot) for roughly $200/month with volume discounts, the kit lets low-skill criminals stand up convincing Microsoft 365-themed login pages (branded 'Login', 'SharePoint', 'OneDrive', 'Microsoft Forms', plus Canva/Tilda/Adobe templates) that proxy the victim's real authentication flow. By relaying the victim's credentials and one-time MFA codes to Microsoft's real login endpoint in real time and capturing the resulting session cookie, operators bypass MFA entirely and hijack authenticated sessions.
The kit incorporates code lineage from the W3LL OV6 AiTM toolkit (first reported by Group-IB in September 2023), sharing identical GuzzleHttp-based cookie-handling and parsing routines and identical blurred Outlook/Excel/OneDrive/SharePoint background images, with an embedded reference to the W3LL domain w3ll[.]store in the authentication relay code. Sneaky 2FA phishing pages first appeared circulating from at least October 2024, were formally identified by Sekoia in December 2024, and Microsoft observed a large-scale W-2/tax-themed campaign (subject: '2025 Employee Tax Docs', attachment 2025_Employee_W-2.docx with a per-recipient QR code) hit roughly 100 US manufacturing, retail, and healthcare organizations on February 10, 2026.
Operationally, the kit uses Cloudflare Turnstile CAPTCHAs to gate the phishing page, filters out datacenter/VPN/security-scanner traffic by redirecting it to benign Wikipedia pages via the href.li anonymizer, displays decoy food-themed HTML during page reloads, obfuscates visible text with interleaved empty anchor tags, base64-encodes images and the spoofed Microsoft favicon, randomizes page titles from a pool of 'Verify/Confirm'-themed strings, and generates 150-character alphanumeric URL paths. A hallmark AiTM tell is that each step of the Microsoft authentication flow (Login:login, SAS:BeginAuth, SAS:ProcessAuth, SAS:EndAuth/Kmsi:kmsi) is relayed with a different hardcoded User-Agent string spanning iOS Safari, Windows Chrome, macOS Firefox, and Windows Edge — inconsistent with a single real device completing one authentication session. Successful sessions were observed redirecting victims to a decoy Outlook error page (outlook.office365[.]com/Encryption/ErrorPage.aspx) to mask the compromise. The operator's back-end license-check server communicated with phishing nodes over HTTP to validate active Sneaky Log subscriptions before serving pages, and cryptocurrency payments (BTC, ETH, LTC, USDT-TRC20/BEP20) were laundered through a fresh-address/overpayment scheme suggestive of a third-party mixing service.
On 2026-07-20/21, Frankfurt's Central Office for Combating Internet Crime (ZIT) and Germany's Federal Criminal Police Office (BKA), working with US law enforcement, Indonesian authorities, and Microsoft, seized more than 200 Kratos servers, transferred seized domains to FBI control with a seizure banner, and arrested the alleged developer/technical administrator in Indonesia. BKA characterized Kratos as 'one of the world's most widely used criminal phishing services,' with confirmed victims in 30-35+ countries (concentrated in the US and Europe) and estimated proceeds exceeding €300,000 (~$342,000) since 2024. Target sectors included US manufacturing, retail, and healthcare organizations, and European industrial firms, law firms, polytechnic institutes, schools, and SMBs.
MITRE ATT&CK techniques used in TL-2026-1602
Collection
Discovery
T1016 System Network Configuration Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials; T1621 Multi-Factor Authentication Request Generation
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service
Initial Access
T1078 Valid Accounts; T1566 Phishing
Persistence
command-and-control
Execution
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Impact
stealth
Affected products and versions in German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
- Microsoft — Microsoft 365 / Entra ID authentication
Vulnerable versions: Any tenant relying solely on OTP/push MFA without phishing-resistant authentication
Fixed in: Tenants enforcing FIDO2/WebAuthn phishing-resistant MFA and continuous access evaluation
Remediation for German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
Immediate actions
- Block confirmed Kratos/SneakyLog phishing infrastructure at email gateway and web proxy (185.125.100.81, 101.99.92.124, sneakylog[.]store, tesla-apply-job[.]com, and the documented SEKOIA-IO domain list)
- Force session revocation and password reset for any accounts that authenticated through a suspected AiTM relay
- Hunt Entra ID / Microsoft 365 sign-in logs for the multi-User-Agent-per-session pattern (iOS Safari on Login:login, then Windows Chrome/macOS Firefox/Windows Edge on subsequent SAS/Kmsi steps within one correlation ID)
- Deploy the Sekoia Sigma correlation rule detecting Login:login (Safari iOS UA) + Login:resume (Edge Windows UA) with identical correlation ID within a 10-minute window
Workarounds
- Block outbound connections to href.li and other open-redirect/anonymizer services used to evade automated analysis
- Flag and quarantine emails with W-2/tax-document-themed subjects and QR-code attachments during tax season
Longer-term hardening
- Migrate high-value accounts to phishing-resistant, FIDO2/WebAuthn-based MFA that is not susceptible to AiTM session-cookie relay
- Enable Microsoft Entra ID Conditional Access token-binding / continuous access evaluation to invalidate stolen session cookies
- Deploy URL/QR-code inspection at the email gateway for W-2 and tax-themed lures with embedded QR codes
- User awareness training on QR-code phishing (quishing) and tax-season lures
Weaknesses (CWE) in German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
CWE-290, CWE-294
Timeline of German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
- Group-IB reports the W3LL OV6 AiTM phishing toolkit, whose GuzzleHttp cookie-handling code and blurred Microsoft-branded background images later appear reused in Sneaky 2FA/Kratos.
- sneakylog[.]store registered, later used as the Sneaky Log license-checking and sales server.
- Sneaky 2FA phishing pages begin circulating in the wild, per Sekoia telemetry.
- Sekoia publishes 'Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service,' documenting infrastructure, Telegram sales bots, and W3LL OV6 code lineage.
- The Hacker News and other outlets report on Sneaky 2FA's 2FA-bypass capability targeting Microsoft 365 accounts.
- KnowBe4 Threat Labs identifies the platform operating under the new name Kratos.
- KnowBe4 publishes 'The Rise of Kratos,' detailing how the PhaaS kit industrializes low-skill phishing operations.
- Microsoft Threat Intelligence observes a Kratos/SneakyLog-built W-2 tax-themed phishing campaign ('2025 Employee Tax Docs', QR-code attachment) hitting ~100 US manufacturing, retail, and healthcare organizations.
- Microsoft Security Blog publishes 'When tax season becomes cyberattack season,' covering Kratos/SneakyLog tax-lure campaigns.
- Kratos activity observed using SharePoint- and Cloudflare-themed bypass techniques shortly before the takedown.
- ZIT Frankfurt, BKA, US law enforcement, Indonesian authorities, and Microsoft execute a coordinated takedown, seizing over 200 Kratos servers and transferring domains to FBI control under a seizure banner.
- German authorities and press (The Register, SC Media, TechRadar) publicly announce the Kratos/SneakyLog/Sneaky 2FA takedown and the arrest of the alleged developer in Indonesia.
Sources cited for German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
- German authorities lead takedown of Kratos phishing platform
- Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
- New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass
- When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures
- The Rise of Kratos: How the New Phishing-as-a-Service Kit Industrializes Cybercrime
- German authorities dismantle Kratos phishing-as-a-service infrastructure
- Microsoft, Europol take down global phishing as a service network which was able to bypass 2FA with ease
- 'Sneaky Log' phishing kits slip by Microsoft 365 accounts
- Sneaky 2FA Malware Analysis, Overview by ANY.RUN
- Sneaky Log Phishing-as-a-Service
- Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
- Police dismantle Kratos phishing platform, arrest developer
Threats related to German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens
- Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit
- International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns
- Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe
Detection coverage for TL-2026-1602
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1602 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.