AI-generated · no human review · verify operationally critical claims against the linked primary source.how it works →
Kratos (phishing-as-a-service)
tool
· tool:kratos-phaas
Adversary-in-the-middle Microsoft 365 phishing-as-a-service platform evolved from the Sneaky2FA kit, offering browser-in-the-browser fake login windows (added November 2025) and Cloudflare Turnstile anti-bot challenges; ~1,800 subscribers ran an estimated 15,000 campaigns/month across 200+ servers. Infrastructure seized and its developer arrested in a German BKA-led takedown with US and Indonesian partners, 2026-07-20 (BKA; Trend Micro, 2026-07-20/22).
3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)
Initial Access TA0001
T1566.002Phishing: Spearphishing Link×1
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Germany's Bundeskriminalamt (BKA), with the Frankfurt cybercrime prosecutor (ZIT), US law enforcement and Indonesian authorities, announced on 20 July 2026 the takedown of Kratos — a phishing-as-a-service (PhaaS) platform that sold subscribers a turnkey adversary-in-the-middle toolkit for generating convincing Microsoft 365 authentication pages (BKA, 2026-07-20). Per BKA and Trend Micro — which had tracked Sneaky2FA's evolution into Kratos since December 2024 — the platform added browser-in-the-browser (BitB) fake login windows in November 2025 and Cloudflare Turnstile anti-bot challenges to blunt automated analysis and takedown, and ran an estimated 15,000 phishing campaigns a month across 200+ servers for roughly 1,800 subscribers (Trend Micro, 2026-07-22). Authorities seized the infrastructure and arrested the platform's developer/technical administrator in Indonesia (BKA, 2026-07-20).
Over 1,800 criminal subscribers had rented access to Kratos and used it to run an estimated 15,000 phishing campaigns a month.