German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA

German-US-Indonesian Law Enforcement Dismantle Kratos (aka (TL-2026-1612), also tracked as SneakyLog, is a high-severity phishing campaign, first published 2026-07-22. It is attributed to Kratos (Indonesia) with high confidence, affects Microsoft Microsoft 365 (Entra ID authentication), maps to 28 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-1612

Threat ID
TL-2026-1612
Also known as
SneakyLog, Sneaky 2FA, Sneaky Log, 365 Cookie Page
Severity
HIGH
Status
MITIGATED
Category
PHISHING
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kratos
Attribution confidence
HIGH
Nation-state nexus
Indonesia
Motivation
FINANCIAL
Target sectors
government administration, finance, health, manufacturing, retail, education, legal, smb, industrial
Target regions
North America, Europe, united states of america, germany
Detection rules
9
Indicators of compromise
24

Malware and tooling in German-US-Indonesian Law Enforcement Dismantle Kratos (aka

Malware and tooling: SneakyLog, 365 Cookie Page, Sneaky 2FA, W3LL OV6, href.li redirection service

German (Frankfurt ZIT, BKA), US, and Indonesian authorities coordinated a takedown of Kratos, a phishing-as-a-service platform also tracked by Microsoft as SneakyLog and publicly linked to the Sneaky 2FA kit, taking 200+ servers offline and arresting the alleged Indonesian developer/technical administrator. The kit used an adversary-in-the-middle (AiTM) Node.js reverse-proxy mode to relay Microsoft 365 logins in real time and steal session cookies, bypassing MFA, and was sold via a Telegram-based franchise model to roughly 1,800 paying customers who ran an estimated 15,000 phishing campaigns per month against hundreds of thousands of potential victims (with ~850 confirmed) across 30-35 countries.

How German-US-Indonesian Law Enforcement Dismantle Kratos (aka works

Kratos is a phishing-as-a-service (PhaaS) platform that German prosecutors (Frankfurt am Main's Central Office for Combating Internet Crime, ZIT) and the Federal Criminal Police Office (BKA), working with US law enforcement and Indonesian authorities, dismantled in a coordinated operation announced July 22, 2026. Open-source and vendor reporting ties the 'Kratos' branding used by German authorities to phishing kits previously and concurrently sold under the names SneakyLog (Microsoft Threat Intelligence's tracking name) and Sneaky 2FA (first documented by Sekoia in December 2024). The platform is best understood as a 'digital construction kit' offered on a subscription/franchise basis: for roughly $200/month (with volume discounts), low-skill 'franchisee' customers received a fully-featured adversary-in-the-middle phishing kit capable of spoofing Microsoft 365, SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and Adobe authentication pages.

Technically, the kit shipped in two modes: (1) a plain PHP credential-harvesting page for simple password theft, and (2) a Node.js reverse-proxy mode that relays the victim's real-time authentication traffic to Microsoft's legitimate login endpoints, transparently forwarding password entry and any MFA/2FA challenge (Authenticator app, SMS, OTP) back to the victim, then capturing the resulting Microsoft 365 session cookie once authentication succeeds. Because the session token is stolen post-authentication, the kit fully bypasses conventional MFA — the operator can replay the harvested cookie to access the victim's mailbox and cloud services without ever possessing the password or a valid MFA response themselves. Source-code analysis (Sekoia, W3LL research lineage) shows Sneaky 2FA/SneakyLog incorporates code derived from the W3LL OV6 phishing kit, evidenced by identical GuzzleHttp cookie-handling and parsing functions, a shared unique UUID embedded in Microsoft-bound requests, and identical blurred-background PNG image hashes.

Operationally, the kit was distributed through a Telegram storefront (primary bot @SneakyLog_bot, with a dedicated support/ticketing bot @SneakySupport_bot) offering the core '365 Cookie Page' AiTM kit alongside adjacent tooling: a 'B2B Sender' bulk spam tool and redirect/attachment services. Payment was cryptocurrency-only (BTC, LTC, ETH, USDT-TRC20/BEP20), with fresh no-history addresses used for BTC/LTC and reused, high-transaction-count addresses for USDT/ETH — a pattern consistent with third-party laundering, reinforced by a roughly 10% payment premium.

The kit is heavily engineered to evade automated analysis and reduce detection: Cloudflare Turnstile CAPTCHA gating, anti-debugger JavaScript blocking browser DevTools, HTML/JS obfuscation via base64-embedded Microsoft branding assets and interspersed junk markup, IP/proxy-based traffic filtering that redirects suspected bots/scanners to benign decoy content (including food-themed pages and Wikipedia redirects via the href.li anonymization service), and a seven-step authentication relay flow (Turnstile challenge → email-based redirect → CAPTCHA → spoofed Microsoft 365 sign-in → password POST to /validate → 2FA method selection → session-token polling). Phishing pages themselves were hosted at URL paths using 150-character alphanumeric tokens followed by /index, /verify, or /validate, served from a mix of attacker-registered domains and compromised WordPress installations, deliberately intermixed with infrastructure shared by other unrelated AiTM kits to complicate attribution and takedown.

A distinctive detection artifact is the kit's inconsistent per-step User-Agent behavior: the initial login step presents an iPhone/Safari 13.0.3 User-Agent, while subsequent server-side authentication (SAS) calls to Microsoft present Chrome/Windows (BeginAuth), Firefox/macOS (ProcessAuth), and Edge/Windows (EndAuth) User-Agents against the same correlation ID within a short window — an 'impossible device shift' that Microsoft 365 audit-log correlation and community Sigma rules use for high-confidence, low-false-positive detection. A second published detection signature is the login page's characteristic paired-asset load of barr.svg and lg.svg immediately prior to POSTing credentials to next.php or save.php, reported at ~90% recall with near-zero false positives.

Microsoft Threat Intelligence has observed SneakyLog-driven campaigns since at least October 2024/early 2025, including a February 10, 2026 tax-season campaign that emailed roughly 100 US organizations in manufacturing, retail, and healthcare with a '2025 Employee Tax Docs' lure, a personalized '2025_Employee_W-2.docx' attachment, and QR codes embedding the recipient's email address to auto-populate the phishing landing page (autograb) — the kit supports both plaintext (#victim@example.com) and base64-encoded (a=<base64(email)>) autograb URL parameters. SneakyLog was one of several PhaaS kits (alongside the larger Energy365 and Tycoon2FA platforms) observed running tax-themed AiTM campaigns during the same window, indicating it competes in — but is not dominant within — the broader commercial PhaaS ecosystem.

The law enforcement action seized and null-routed 200+ servers, ending Kratos-supported campaigns' ability to execute, and resulted in the arrest of the platform's alleged developer/technical administrator in Indonesia. Officials estimate the operation generated 300,000+ (~$342,000 USD) in criminal revenue since operations began (reporting variably places kit origin between late 2024 and January 2026), ran roughly 15,000 monthly phishing campaigns against a potential victim pool of hundreds of thousands (with ~850 victims formally identified across 35 countries, concentrated in Europe and the United States), and served approximately 1,800 paying subscriber/franchisee accounts. BKA cybercrime chief Carsten Meywirth stated: 'Anyone who steals login credentials online using fake websites shouldn't feel safe.' Despite the takedown, the ~1,800 customers retain kit source code and Telegram access, and investigators expect the operation — or its customer base — to resurface under new branding, consistent with prior PhaaS takedowns (e.g., 16shop, LabHost).

MITRE ATT&CK techniques used in TL-2026-1612

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service

Discovery

T1087 Account Discovery; T1526 Cloud Service Discovery

Persistence

T1098 Account Manipulation

command-and-control

T1102 Web Service

collection

T1114 Email Collection

Initial Access

T1199 Trusted Relationship; T1566 Phishing

Collection

T1213 Data from Information Repositories

Impact

T1531 Account Access Removal

defense-impairment

T1556 Modify Authentication Process

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

stealth

T1684.001 Impersonation

Affected products and versions in German-US-Indonesian Law Enforcement Dismantle Kratos (aka

  • Microsoft — Microsoft 365 (Entra ID authentication)
    Vulnerable versions: all cloud tenants using password/OTP-based MFA
    Fixed in: accounts enforcing phishing-resistant FIDO2/WebAuthn MFA and Conditional Access token binding
  • Microsoft — SharePoint Online
    Vulnerable versions: cloud tenants targeted via spoofed sign-in lures
  • Microsoft — OneDrive
    Vulnerable versions: cloud tenants targeted via spoofed sign-in lures
  • Microsoft — Microsoft Forms
    Vulnerable versions: used as spoofed lure surface
  • Canva — Canva
    Vulnerable versions: used as spoofed lure surface
  • Tilda — Tilda
    Vulnerable versions: used as spoofed lure surface
  • Adobe — Adobe products (sign-in pages)
    Vulnerable versions: used as spoofed lure surface

Remediation for German-US-Indonesian Law Enforcement Dismantle Kratos (aka

Immediate actions

  • Block known Kratos/SneakyLog/Sneaky 2FA infrastructure (sneakylog[.]store, 185.125.100[.]81, tesla-apply-job[.]com, and community IOC feed) at email gateway, proxy, and DNS layers
  • Hunt Microsoft 365 / Entra ID sign-in and audit logs for impossible device/User-Agent shifts within the same session correlation ID (iPhone Safari -> Chrome Windows -> Firefox macOS -> Edge Windows) within a short time window
  • Search web/proxy logs for paired asset requests to barr.svg and lg.svg followed by POSTs to next.php, save.php, or /validate paths
  • Revoke and re-issue session tokens for any account showing anomalous sign-in patterns; force password + MFA re-enrollment
  • Review mailbox inbox rules, delegate access, and forwarding rules for unauthorized changes following any suspected compromise

Workarounds

  • Block QR-code-based phishing lures and enforce manual URL entry / non-clickable link policies for tax-season and HR-themed emails
  • User awareness training on QR-code phishing, W-2/tax-document lures, and multi-stage redirect chains abusing legitimate services (OneDrive, carrd.co, URL shorteners, href.li)

Longer-term hardening

  • Migrate high-value and privileged accounts to phishing-resistant MFA (FIDO2/WebAuthn security keys, certificate-based authentication) since OTP/push-based MFA is bypassed by AiTM session-cookie theft
  • Deploy Conditional Access policies with token binding/continuous access evaluation to reduce the value of stolen session cookies
  • Enable Microsoft Defender for Office 365 Safe Links with click-time re-evaluation and Zero-Hour Auto Purge (ZAP)
  • Deploy the published community Sigma correlation rule detecting impossible-device-shift authentication patterns in SIEM/XDR
  • Maintain awareness that PhaaS kit branding (Kratos/SneakyLog/Sneaky 2FA) and infrastructure will likely reappear under new names post-takedown; treat the underlying kit signatures, not the brand name, as the durable detection surface

Weaknesses (CWE) in German-US-Indonesian Law Enforcement Dismantle Kratos (aka

CWE-290, CWE-294, CWE-1021

Timeline of German-US-Indonesian Law Enforcement Dismantle Kratos (aka

  • Source-code lineage traced by Sekoia places the underlying W3LL OV6 phishing kit codebase (later incorporated into Sneaky 2FA/SneakyLog) in active development between May 9 and June 20, 2023.
  • Microsoft Threat Intelligence and independent researchers observe SneakyLog/Sneaky 2FA AiTM phishing activity beginning, associated with roughly 100 domains.
  • Sekoia publishes 'Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service,' the first detailed public technical analysis of the kit, including its Telegram bot storefront and W3LL OV6 code lineage.
  • TechRepublic, SC Media, and the NJCCIC (New Jersey Cybersecurity Cell) publish advisories on 'Sneaky Log' phishing-as-a-service targeting Microsoft 365 accounts and bypassing 2FA.
  • SneakyLog-driven phishing campaign emails approximately 100 US organizations in manufacturing, retail, and healthcare with a '2025 Employee Tax Docs' lure containing a personalized W-2 document and QR code autograb links to a spoofed Microsoft 365 sign-in page.
  • Microsoft Security Blog publishes 'When tax season becomes cyberattack season,' documenting the SneakyLog campaign alongside larger PhaaS competitors Energy365 and Tycoon2FA.
  • The Register reports the coordinated German-led (ZIT Frankfurt, BKA), US, and Indonesian law enforcement takedown of the Kratos PhaaS platform, taking 200+ servers offline.
  • Security researchers assess that while Kratos-branded infrastructure is offline, the ~1,800 customer base retains kit source code and Telegram access, and the operation is expected to resurface under new branding, consistent with prior PhaaS takedown patterns (e.g., 16shop, LabHost).
  • BKA and Frankfurt prosecutors formally announce the Kratos takedown via press release; The Hacker News and GBHackers publish coverage confirming the arrest of the alleged Indonesian developer/administrator, ~1,800 subscriber accounts, ~15,000 monthly campaigns, and victims across 30-35 countries.

Sources cited for German-US-Indonesian Law Enforcement Dismantle Kratos (aka

Threats related to German-US-Indonesian Law Enforcement Dismantle Kratos (aka

Detection coverage for TL-2026-1612

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1612 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats