International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns — Threadlinqs Intelligence
As of 2026-07-22, International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns is a medium-severity phishing threat attributed to Kratos PhaaS developer, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1608 · Severity: MEDIUM · Status: RESOLVED · Category: PHISHING
Attribution: Kratos PhaaS developer · FINANCIAL
Germany's BKA and the Frankfurt ZIT, working with U.S. and Indonesian authorities, dismantled Kratos — a subscription-based phishing-as-a-service (PhaaS) platform also marketed as SneakyLog/Sneaky 2FA
Kratos was a criminal 'digital construction kit' — a phishing-as-a-service (PhaaS) offering that lowered the technical barrier for account-takeover fraud by leasing ready-made, adversary-in-the-middle (AiTM) capable phishing infrastructure to subscribers. Operating from 2020 through 2024 and generating over €300,000 in sales/subscription revenue, the platform is estimated to have onboarded more than 1,800 criminal customers who together launched approximately 15,000 phishing campaigns per month. Independent technical analysis (ANY.RUN sandbox telemetry, cross-referenced with KnowBe4 and Microsoft reporting under the aliases 'SneakyLog' and 'Sneaky 2FA') documented three generations of the kit (V0/PTT-SOft, V1, V2), each replicating Microsoft 365/Azure AD authentication flows and associated services (SharePoint, OneDrive, Microsoft Forms) to harvest usernames, passwords, and session cookies capable of bypassing multi-factor authentication.
Victims were lured via emails impersonating document-sharing notifications, DocuSign, and invoice/billing alerts, frequently staged through abused legitimate SaaS intermediaries (SharePoint, OneDrive, Canva, Tilda, systeme.io, Adobe, Microsoft Forms) to evade corporate email filters, and delivered via QR codes, ICS calendar invites, EML attachments, and weaponized PDF/DOCX lures. The kit's admin panel let operators choose between a PHP-based Office 365 impersonation page or a Node.js redirect server with built-in anti-bot protection, deploy domains, upload files, install SSL certificates, and modify DNS — protected by a master password plus Telegram-based two-factor authentication (in use since at least September 10, 2025). Anti-analysis measures included Cloudflare Turnstile/reCAPTCHA/hCaptcha challenges, geolocation/device filtering via geoplugin.net, and a hard three-attempt password limit designed to defeat automated sandboxes while still harvesting real credentials from human victims. Harvested credentials were packaged as JSON and exfiltrated via the Telegram Bot API, keeping stolen data available to operators even after infrastructure takedowns.
Infrastructure relied on disposable domains registered on low-cost TLDs (.horse, .cfd, .sbs, .today, .fit, .online) alongside compromised legitimate WordPress sites (concentrated in German .de and Spanish .es domains), fronted by Cloudflare to mask true origin hosting across Azure, Google Cloud, and Host4Geeks. Sandbox telemetry logged 1,628 phishing sessions across 20+ countries, with 148 suspected victim organizations identified via harvested SharePoint tenant names; targeting concentrated on SMBs, law firms, schools/polytechnics, and industrial organizations in Europe (notably Spain, evidenced by Spanish-language lure tokens such as 'factura', 'abogados', 'dgt') and manufacturing, retail, and healthcare organizations in the United States. The July 2026 operation — the result of a joint BKA/ZIT (Frankfurt Central Office for Combating Internet Crime)/U.S./Indonesian investigation — seized over 200 servers and arrested Kratos's alleged developer and technical administrator in Indonesia, with BKA cybercrime chief Carsten Meywirth and ZIT head Benjamin Krause publicly confirming the platform's central infrastructure has been disrupted such that Kratos-supported campaigns can no longer be executed.
Target sectors: manufacturing, retail, health, law-firms, education, smb, industrial
Target regions: North America, Europe
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1583, T1584, T1608, T1566, T1598, T1204, T1027, T1497, T1036, T1557