German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft — Threadlinqs Intelligence
As of 2026-07-22, German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft is a high-severity phishing threat attributed to Kratos, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1602 · Severity: HIGH · Status: MITIGATED · Category: PHISHING
Attribution: Kratos · FINANCIAL
German authorities (Frankfurt ZIT, BKA), supported by US law enforcement and Microsoft, dismantled Kratos — also known as SneakyLog and Sneaky 2FA — an adversary-in-the-middle phishing-as-a-service
Kratos is a phishing-as-a-service (PhaaS) kit that evolved from an earlier family of commercial trojans and infostealers into a subscription-based adversary-in-the-middle (AiTM) platform marketed under the names SneakyLog and Sneaky 2FA. Sold via a Telegram bot (@SneakyLog_bot) for roughly $200/month with volume discounts, the kit lets low-skill criminals stand up convincing Microsoft 365-themed login pages (branded 'Login', 'SharePoint', 'OneDrive', 'Microsoft Forms', plus Canva/Tilda/Adobe templates) that proxy the victim's real authentication flow. By relaying the victim's credentials and one-time MFA codes to Microsoft's real login endpoint in real time and capturing the resulting session cookie, operators bypass MFA entirely and hijack authenticated sessions.
The kit incorporates code lineage from the W3LL OV6 AiTM toolkit (first reported by Group-IB in September 2023), sharing identical GuzzleHttp-based cookie-handling and parsing routines and identical blurred Outlook/Excel/OneDrive/SharePoint background images, with an embedded reference to the W3LL domain w3ll[.]store in the authentication relay code. Sneaky 2FA phishing pages first appeared circulating from at least October 2024, were formally identified by Sekoia in December 2024, and Microsoft observed a large-scale W-2/tax-themed campaign (subject: '2025 Employee Tax Docs', attachment 2025_Employee_W-2.docx with a per-recipient QR code) hit roughly 100 US manufacturing, retail, and healthcare organizations on February 10, 2026.
Operationally, the kit uses Cloudflare Turnstile CAPTCHAs to gate the phishing page, filters out datacenter/VPN/security-scanner traffic by redirecting it to benign Wikipedia pages via the href.li anonymizer, displays decoy food-themed HTML during page reloads, obfuscates visible text with interleaved empty anchor tags, base64-encodes images and the spoofed Microsoft favicon, randomizes page titles from a pool of 'Verify/Confirm'-themed strings, and generates 150-character alphanumeric URL paths. A hallmark AiTM tell is that each step of the Microsoft authentication flow (Login:login, SAS:BeginAuth, SAS:ProcessAuth, SAS:EndAuth/Kmsi:kmsi) is relayed with a different hardcoded User-Agent string spanning iOS Safari, Windows Chrome, macOS Firefox, and Windows Edge — inconsistent with a single real device completing one authentication session. Successful sessions were observed redirecting victims to a decoy Outlook error page (outlook.office365[.]com/Encryption/ErrorPage.aspx) to mask the compromise. The operator's back-end license-check server communicated with phishing nodes over HTTP to validate active Sneaky Log subscriptions before serving pages, and cryptocurrency payments (BTC, ETH, LTC, USDT-TRC20/BEP20) were laundered through a fresh-address/overpayment scheme suggestive of a third-party mixing service.
On 2026-07-20/21, Frankfurt's Central Office for Combating Internet Crime (ZIT) and Germany's Federal Criminal Police Office (BKA), working with US law enforcement, Indonesian authorities, and Microsoft, seized more than 200 Kratos servers, transferred seized domains to FBI control with a seizure banner, and arrested the alleged developer/technical administrator in Indonesia. BKA characterized Kratos as 'one of the world's most widely used criminal phishing services,' with confirmed victims in 30-35+ countries (concentrated in the US and Europe) and estimated proceeds exceeding €300,000 (~$342,000) since 2024. Target sectors included US manufacturing, retail, and healthcare organizations, and European industrial firms, law firms, polytechnic institutes, schools, and SMBs.
Weaknesses (CWE)
CWE-290, CWE-294
Target sectors: manufacturing, retail, health, industrial, legal, education, government administration, finance, technology
Target regions: united states of america, Europe, germany, indonesia
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1587, T1585, T1566, T1566, T1566, T1078, T1204, T1098