German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft

German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) (TL-2026-1602), also tracked as Kratos, is a high-severity phishing campaign, first published 2026-07-22. It is attributed to Kratos with medium confidence, affects Microsoft Microsoft 365 / Entra ID authentication, maps to 25 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-1602

Threat ID
TL-2026-1602
Also known as
Kratos, SneakyLog, Sneaky 2FA, Sneaky Log, Operation Olympus Blade
Severity
HIGH
Status
MITIGATED
Category
PHISHING
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kratos
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, retail, health, industrial, legal, education, government administration, finance, technology
Target regions
united states of america, Europe, germany, indonesia
Detection rules
9
Indicators of compromise
29

Malware and tooling in German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

Malware and tooling: Kratos, Sneaky 2FA, W3LL OV6, SneakyLog_bot, SneakySupport_bot, href.li

German authorities (Frankfurt ZIT, BKA), supported by US law enforcement and Microsoft, dismantled Kratos — also known as SneakyLog and Sneaky 2FA — an adversary-in-the-middle phishing-as-a-service platform that harvested Microsoft 365 credentials and session cookies to bypass MFA. Roughly 1,800 criminal customers ran ~15,000 phishing campaigns per month against victims in 30+ countries; over 200 servers were seized and the alleged developer was arrested in Indonesia.

How German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) works

Kratos is a phishing-as-a-service (PhaaS) kit that evolved from an earlier family of commercial trojans and infostealers into a subscription-based adversary-in-the-middle (AiTM) platform marketed under the names SneakyLog and Sneaky 2FA. Sold via a Telegram bot (@SneakyLog_bot) for roughly $200/month with volume discounts, the kit lets low-skill criminals stand up convincing Microsoft 365-themed login pages (branded 'Login', 'SharePoint', 'OneDrive', 'Microsoft Forms', plus Canva/Tilda/Adobe templates) that proxy the victim's real authentication flow. By relaying the victim's credentials and one-time MFA codes to Microsoft's real login endpoint in real time and capturing the resulting session cookie, operators bypass MFA entirely and hijack authenticated sessions.

The kit incorporates code lineage from the W3LL OV6 AiTM toolkit (first reported by Group-IB in September 2023), sharing identical GuzzleHttp-based cookie-handling and parsing routines and identical blurred Outlook/Excel/OneDrive/SharePoint background images, with an embedded reference to the W3LL domain w3ll[.]store in the authentication relay code. Sneaky 2FA phishing pages first appeared circulating from at least October 2024, were formally identified by Sekoia in December 2024, and Microsoft observed a large-scale W-2/tax-themed campaign (subject: '2025 Employee Tax Docs', attachment 2025_Employee_W-2.docx with a per-recipient QR code) hit roughly 100 US manufacturing, retail, and healthcare organizations on February 10, 2026.

Operationally, the kit uses Cloudflare Turnstile CAPTCHAs to gate the phishing page, filters out datacenter/VPN/security-scanner traffic by redirecting it to benign Wikipedia pages via the href.li anonymizer, displays decoy food-themed HTML during page reloads, obfuscates visible text with interleaved empty anchor tags, base64-encodes images and the spoofed Microsoft favicon, randomizes page titles from a pool of 'Verify/Confirm'-themed strings, and generates 150-character alphanumeric URL paths. A hallmark AiTM tell is that each step of the Microsoft authentication flow (Login:login, SAS:BeginAuth, SAS:ProcessAuth, SAS:EndAuth/Kmsi:kmsi) is relayed with a different hardcoded User-Agent string spanning iOS Safari, Windows Chrome, macOS Firefox, and Windows Edge — inconsistent with a single real device completing one authentication session. Successful sessions were observed redirecting victims to a decoy Outlook error page (outlook.office365[.]com/Encryption/ErrorPage.aspx) to mask the compromise. The operator's back-end license-check server communicated with phishing nodes over HTTP to validate active Sneaky Log subscriptions before serving pages, and cryptocurrency payments (BTC, ETH, LTC, USDT-TRC20/BEP20) were laundered through a fresh-address/overpayment scheme suggestive of a third-party mixing service.

On 2026-07-20/21, Frankfurt's Central Office for Combating Internet Crime (ZIT) and Germany's Federal Criminal Police Office (BKA), working with US law enforcement, Indonesian authorities, and Microsoft, seized more than 200 Kratos servers, transferred seized domains to FBI control with a seizure banner, and arrested the alleged developer/technical administrator in Indonesia. BKA characterized Kratos as 'one of the world's most widely used criminal phishing services,' with confirmed victims in 30-35+ countries (concentrated in the US and Europe) and estimated proceeds exceeding €300,000 (~$342,000) since 2024. Target sectors included US manufacturing, retail, and healthcare organizations, and European industrial firms, law firms, polytechnic institutes, schools, and SMBs.

MITRE ATT&CK techniques used in TL-2026-1602

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials; T1621 Multi-Factor Authentication Request Generation

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service

Initial Access

T1078 Valid Accounts; T1566 Phishing

Persistence

T1098 Account Manipulation

command-and-control

T1102 Web Service

Execution

T1204 User Execution

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

  • Microsoft — Microsoft 365 / Entra ID authentication
    Vulnerable versions: Any tenant relying solely on OTP/push MFA without phishing-resistant authentication
    Fixed in: Tenants enforcing FIDO2/WebAuthn phishing-resistant MFA and continuous access evaluation

Remediation for German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

Immediate actions

  • Block confirmed Kratos/SneakyLog phishing infrastructure at email gateway and web proxy (185.125.100.81, 101.99.92.124, sneakylog[.]store, tesla-apply-job[.]com, and the documented SEKOIA-IO domain list)
  • Force session revocation and password reset for any accounts that authenticated through a suspected AiTM relay
  • Hunt Entra ID / Microsoft 365 sign-in logs for the multi-User-Agent-per-session pattern (iOS Safari on Login:login, then Windows Chrome/macOS Firefox/Windows Edge on subsequent SAS/Kmsi steps within one correlation ID)
  • Deploy the Sekoia Sigma correlation rule detecting Login:login (Safari iOS UA) + Login:resume (Edge Windows UA) with identical correlation ID within a 10-minute window

Workarounds

  • Block outbound connections to href.li and other open-redirect/anonymizer services used to evade automated analysis
  • Flag and quarantine emails with W-2/tax-document-themed subjects and QR-code attachments during tax season

Longer-term hardening

  • Migrate high-value accounts to phishing-resistant, FIDO2/WebAuthn-based MFA that is not susceptible to AiTM session-cookie relay
  • Enable Microsoft Entra ID Conditional Access token-binding / continuous access evaluation to invalidate stolen session cookies
  • Deploy URL/QR-code inspection at the email gateway for W-2 and tax-themed lures with embedded QR codes
  • User awareness training on QR-code phishing (quishing) and tax-season lures

Weaknesses (CWE) in German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

CWE-290, CWE-294

Timeline of German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

  • Group-IB reports the W3LL OV6 AiTM phishing toolkit, whose GuzzleHttp cookie-handling code and blurred Microsoft-branded background images later appear reused in Sneaky 2FA/Kratos.
  • sneakylog[.]store registered, later used as the Sneaky Log license-checking and sales server.
  • Sneaky 2FA phishing pages begin circulating in the wild, per Sekoia telemetry.
  • Sekoia publishes 'Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service,' documenting infrastructure, Telegram sales bots, and W3LL OV6 code lineage.
  • The Hacker News and other outlets report on Sneaky 2FA's 2FA-bypass capability targeting Microsoft 365 accounts.
  • KnowBe4 Threat Labs identifies the platform operating under the new name Kratos.
  • KnowBe4 publishes 'The Rise of Kratos,' detailing how the PhaaS kit industrializes low-skill phishing operations.
  • Microsoft Threat Intelligence observes a Kratos/SneakyLog-built W-2 tax-themed phishing campaign ('2025 Employee Tax Docs', QR-code attachment) hitting ~100 US manufacturing, retail, and healthcare organizations.
  • Microsoft Security Blog publishes 'When tax season becomes cyberattack season,' covering Kratos/SneakyLog tax-lure campaigns.
  • Kratos activity observed using SharePoint- and Cloudflare-themed bypass techniques shortly before the takedown.
  • ZIT Frankfurt, BKA, US law enforcement, Indonesian authorities, and Microsoft execute a coordinated takedown, seizing over 200 Kratos servers and transferring domains to FBI control under a seizure banner.
  • German authorities and press (The Register, SC Media, TechRadar) publicly announce the Kratos/SneakyLog/Sneaky 2FA takedown and the arrest of the alleged developer in Indonesia.

Sources cited for German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

Threats related to German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA)

Detection coverage for TL-2026-1602

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1602 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats