International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns

International Law Enforcement Dismantles Kratos (TL-2026-1608), also tracked as SneakyLog, is a medium-severity phishing campaign, first published 2026-07-22. It is attributed to Kratos PhaaS developer with medium confidence, affects Microsoft Microsoft 365 / Azure AD authentication (SharePoint, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-1608

Threat ID
TL-2026-1608
Also known as
SneakyLog, Sneaky 2FA
Severity
MEDIUM
Status
RESOLVED
Category
PHISHING
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kratos PhaaS developer
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, retail, health, law-firms, education, smb, industrial
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
31

Malware and tooling in International Law Enforcement Dismantles Kratos

Malware and tooling: Sneaky 2FA, SneakyLog, Cloudflare Turnstile / reCAPTCHA / hCaptcha challenge pages

Germany's BKA and the Frankfurt ZIT, working with U.S. and Indonesian authorities, dismantled Kratos — a subscription-based phishing-as-a-service (PhaaS) platform also marketed as SneakyLog/Sneaky 2FA that generated adversary-in-the-middle counterfeit Microsoft 365 login pages to steal credentials, session cookies, and MFA tokens. The takedown neutralized over 200 servers and led to the arrest of the platform's developer/administrator in Indonesia; roughly 1,800 criminal subscribers had used the kit since 2020 to run ~15,000 monthly campaigns against an estimated 850 victims in 35 countries.

How International Law Enforcement Dismantles Kratos works

Kratos was a criminal 'digital construction kit' — a phishing-as-a-service (PhaaS) offering that lowered the technical barrier for account-takeover fraud by leasing ready-made, adversary-in-the-middle (AiTM) capable phishing infrastructure to subscribers. Operating from 2020 through 2024 and generating over €300,000 in sales/subscription revenue, the platform is estimated to have onboarded more than 1,800 criminal customers who together launched approximately 15,000 phishing campaigns per month. Independent technical analysis (ANY.RUN sandbox telemetry, cross-referenced with KnowBe4 and Microsoft reporting under the aliases 'SneakyLog' and 'Sneaky 2FA') documented three generations of the kit (V0/PTT-SOft, V1, V2), each replicating Microsoft 365/Azure AD authentication flows and associated services (SharePoint, OneDrive, Microsoft Forms) to harvest usernames, passwords, and session cookies capable of bypassing multi-factor authentication.

Victims were lured via emails impersonating document-sharing notifications, DocuSign, and invoice/billing alerts, frequently staged through abused legitimate SaaS intermediaries (SharePoint, OneDrive, Canva, Tilda, systeme.io, Adobe, Microsoft Forms) to evade corporate email filters, and delivered via QR codes, ICS calendar invites, EML attachments, and weaponized PDF/DOCX lures. The kit's admin panel let operators choose between a PHP-based Office 365 impersonation page or a Node.js redirect server with built-in anti-bot protection, deploy domains, upload files, install SSL certificates, and modify DNS — protected by a master password plus Telegram-based two-factor authentication (in use since at least September 10, 2025). Anti-analysis measures included Cloudflare Turnstile/reCAPTCHA/hCaptcha challenges, geolocation/device filtering via geoplugin.net, and a hard three-attempt password limit designed to defeat automated sandboxes while still harvesting real credentials from human victims. Harvested credentials were packaged as JSON and exfiltrated via the Telegram Bot API, keeping stolen data available to operators even after infrastructure takedowns.

Infrastructure relied on disposable domains registered on low-cost TLDs (.horse, .cfd, .sbs, .today, .fit, .online) alongside compromised legitimate WordPress sites (concentrated in German .de and Spanish .es domains), fronted by Cloudflare to mask true origin hosting across Azure, Google Cloud, and Host4Geeks. Sandbox telemetry logged 1,628 phishing sessions across 20+ countries, with 148 suspected victim organizations identified via harvested SharePoint tenant names; targeting concentrated on SMBs, law firms, schools/polytechnics, and industrial organizations in Europe (notably Spain, evidenced by Spanish-language lure tokens such as 'factura', 'abogados', 'dgt') and manufacturing, retail, and healthcare organizations in the United States. The July 2026 operation — the result of a joint BKA/ZIT (Frankfurt Central Office for Combating Internet Crime)/U.S./Indonesian investigation — seized over 200 servers and arrested Kratos's alleged developer and technical administrator in Indonesia, with BKA cybercrime chief Carsten Meywirth and ZIT head Benjamin Krause publicly confirming the platform's central infrastructure has been disrupted such that Kratos-supported campaigns can no longer be executed.

MITRE ATT&CK techniques used in TL-2026-1608

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Discovery

T1087 Account Discovery

Command and Control

T1102 Web Service

Collection

T1119 Automated Collection

Execution

T1204 User Execution

Credential Access

T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle

Impact

T1531 Account Access Removal

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1608 Stage Capabilities

reconnaissance

T1598 Phishing for Information

Affected products and versions in International Law Enforcement Dismantles Kratos

  • Microsoft — Microsoft 365 / Azure AD authentication (SharePoint, OneDrive, Microsoft Forms login flows)
    Vulnerable versions: N/A - phishing kit impersonates hosted login flow, not a software vulnerability
    Fixed in: N/A

Remediation for International Law Enforcement Dismantles Kratos

Immediate actions

  • Block the disclosed Kratos/SneakyLog phishing domains and the operator IP 41.128.0.142 at email gateway and web proxy
  • Hunt proxy/EDR logs for HTTP requests to */assets/img/barr.svg and */assets/img/lg.svg (or */dsa.svg, */sid.gif, */imag.jpg) within the same session — documented ~90% recall fingerprint for this kit
  • Force password resets and session/refresh-token revocation for any user who submitted credentials to a matching counterfeit Microsoft 365 login page
  • Review Telegram Bot API (api.telegram.org) traffic originating from internal hosts as a possible indicator of AiTM relay or credential exfiltration

Workarounds

  • User training to verify authentication URLs before entering Microsoft 365 credentials, especially links delivered via document-share, DocuSign, or invoice-themed email lures

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2 security keys, passkeys) to eliminate session-cookie/OTP-relay AiTM bypass
  • Deploy conditional access / token-binding policies to invalidate stolen session cookies used outside expected device/location context
  • Continuously monitor for newly registered lookalike domains on low-cost TLDs (.cfd, .sbs, .today, .fit, .online, .horse) impersonating Microsoft branding
  • Add detection content (email, proxy, EDR) for QR-code, ICS-calendar, and EML-attachment phishing delivery vectors, not just link-based phishing

Timeline of International Law Enforcement Dismantles Kratos

  • Kratos phishing-as-a-service platform begins operating, per BKA/ZIT investigation covering the 2020-2024 activity window.
  • Kratos's documented criminal operating window (2020-2024) closes, having generated over €300,000 in sales/subscription revenue from ~1,800 customers.
  • Microsoft reporting places initial in-the-wild observation of the kit (later tracked as SneakyLog/Sneaky 2FA) around early 2025.
  • Kratos admin panel Telegram-based two-factor authentication protection recorded as active from this date, per ANY.RUN sandbox analysis.
  • KnowBe4 publishes analysis dating Kratos's market entry to January 2026, industrializing PhaaS-driven Microsoft 365 credential phishing.
  • Kratos's alleged developer and technical administrator is arrested in Indonesia as part of the coordinated operation.
  • BKA and Frankfurt ZIT publicly announce the joint German/U.S./Indonesian takedown of Kratos's central infrastructure, seizing over 200 servers.
  • The Register, SC Media, and other outlets publish detailed coverage of the takedown, confirming disruption prevents further Kratos-supported campaigns.
  • GBHackers publishes the takedown summary that triggered this threat-intelligence hunt entry.

Sources cited for International Law Enforcement Dismantles Kratos

Threats related to International Law Enforcement Dismantles Kratos

Detection coverage for TL-2026-1608

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1608 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1608

5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats