German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA — Threadlinqs Intelligence
As of 2026-07-22, German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA is a high-severity phishing threat attributed to Kratos (aka SneakyLog (Indonesia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1612 · Severity: HIGH · Status: MITIGATED · Category: PHISHING
Attribution: Kratos (aka SneakyLog · Indonesia · FINANCIAL
German (Frankfurt ZIT, BKA), US, and Indonesian authorities coordinated a takedown of Kratos, a phishing-as-a-service platform also tracked by Microsoft as SneakyLog and publicly linked to the Sneaky
Kratos is a phishing-as-a-service (PhaaS) platform that German prosecutors (Frankfurt am Main's Central Office for Combating Internet Crime, ZIT) and the Federal Criminal Police Office (BKA), working with US law enforcement and Indonesian authorities, dismantled in a coordinated operation announced July 22, 2026. Open-source and vendor reporting ties the 'Kratos' branding used by German authorities to phishing kits previously and concurrently sold under the names SneakyLog (Microsoft Threat Intelligence's tracking name) and Sneaky 2FA (first documented by Sekoia in December 2024). The platform is best understood as a 'digital construction kit' offered on a subscription/franchise basis: for roughly $200/month (with volume discounts), low-skill 'franchisee' customers received a fully-featured adversary-in-the-middle phishing kit capable of spoofing Microsoft 365, SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and Adobe authentication pages.
Technically, the kit shipped in two modes: (1) a plain PHP credential-harvesting page for simple password theft, and (2) a Node.js reverse-proxy mode that relays the victim's real-time authentication traffic to Microsoft's legitimate login endpoints, transparently forwarding password entry and any MFA/2FA challenge (Authenticator app, SMS, OTP) back to the victim, then capturing the resulting Microsoft 365 session cookie once authentication succeeds. Because the session token is stolen post-authentication, the kit fully bypasses conventional MFA — the operator can replay the harvested cookie to access the victim's mailbox and cloud services without ever possessing the password or a valid MFA response themselves. Source-code analysis (Sekoia, W3LL research lineage) shows Sneaky 2FA/SneakyLog incorporates code derived from the W3LL OV6 phishing kit, evidenced by identical GuzzleHttp cookie-handling and parsing functions, a shared unique UUID embedded in Microsoft-bound requests, and identical blurred-background PNG image hashes.
Operationally, the kit was distributed through a Telegram storefront (primary bot @SneakyLog_bot, with a dedicated support/ticketing bot @SneakySupport_bot) offering the core '365 Cookie Page' AiTM kit alongside adjacent tooling: a 'B2B Sender' bulk spam tool and redirect/attachment services. Payment was cryptocurrency-only (BTC, LTC, ETH, USDT-TRC20/BEP20), with fresh no-history addresses used for BTC/LTC and reused, high-transaction-count addresses for USDT/ETH — a pattern consistent with third-party laundering, reinforced by a roughly 10% payment premium.
The kit is heavily engineered to evade automated analysis and reduce detection: Cloudflare Turnstile CAPTCHA gating, anti-debugger JavaScript blocking browser DevTools, HTML/JS obfuscation via base64-embedded Microsoft branding assets and interspersed junk markup, IP/proxy-based traffic filtering that redirects suspected bots/scanners to benign decoy content (including food-themed pages and Wikipedia redirects via the href.li anonymization service), and a seven-step authentication relay flow (Turnstile challenge → email-based redirect → CAPTCHA → spoofed Microsoft 365 sign-in → password POST to /validate → 2FA method selection → session-token polling). Phishing pages themselves were hosted at URL paths using 150-character alphanumeric tokens followed by /index, /verify, or /validate, served from a mix of attacker-registered domains and compromised WordPress installations, deliberately intermixed with infrastructure shared by other unrelated AiTM kits to complicate attribution and takedown.
A distinctive detection artifact is the kit's inconsistent per-step User-Agent behavior: the initial login step presents an iPhone/Safari 13.0.3 User-Agent, while subsequent server-side authentication (SAS) calls to Microsoft present Chrome/Windows (BeginAuth), Firefox/macOS (ProcessAuth), and Edge/Windows (EndAuth) User-Agents against the same correlation ID within a short window — an 'impossible device shift' that Micr
Weaknesses (CWE)
CWE-290, CWE-294, CWE-1021
Target sectors: government administration, finance, health, manufacturing, retail, education, legal, smb, industrial
Target regions: North America, Europe, united states of america, germany
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1584, T1587, T1588, T1585, T1566, T1566, T1566, T1199