ctipilot.ch

Kratos (phishing-as-a-service)

tool · tool:kratos-phaas

Adversary-in-the-middle Microsoft 365 phishing-as-a-service platform evolved from the Sneaky2FA kit, offering browser-in-the-browser fake login windows (added November 2025) and Cloudflare Turnstile anti-bot challenges; ~1,800 subscribers ran an estimated 15,000 campaigns/month across 200+ servers. Infrastructure seized and its developer arrested in a German BKA-led takedown with US and Indonesian partners, 2026-07-20 (BKA; Trend Micro, 2026-07-20/22).

Aliases: Sneaky2FA

Coverage timeline
1
first 2026-07-24 → last 2026-07-24
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
3
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Microsoft 365

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566.002Phishing: Spearphishing Link×1

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-07-24/kratos-phaas-takedown-bka-sneaky2fa-m365-aitm · ATT&CK page ↗

Credential Access TA0006

T1539Steal Web Session Cookie×1

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-07-24/kratos-phaas-takedown-bka-sneaky2fa-m365-aitm · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-24/kratos-phaas-takedown-bka-sneaky2fa-m365-aitm · ATT&CK page ↗

Collection TA0009

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-24/kratos-phaas-takedown-bka-sneaky2fa-m365-aitm · ATT&CK page ↗

Story timeline

  1. 2026-07-24German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns
    active-threatsA German-led takedown removes Kratos's infrastructure — but the AiTM tradecraft and affiliate base survive, as Tycoon2FA already showed

Where this entity is cited

  • active-threats1

Source distribution

  • bka.de1 (50%)
  • trendmicro.com1 (50%)

explore in graph

Entries about Kratos (phishing-as-a-service) (1)

2026-07-24 · view entry permalink →

NOTABLENATOA1

German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns

Germany's Bundeskriminalamt (BKA), with the Frankfurt cybercrime prosecutor (ZIT), US law enforcement and Indonesian authorities, announced on 20 July 2026 the takedown of Kratos — a phishing-as-a-service (PhaaS) platform that sold subscribers a turnkey adversary-in-the-middle toolkit for generating convincing Microsoft 365 authentication pages (BKA, 2026-07-20). Per BKA and Trend Micro — which had tracked Sneaky2FA's evolution into Kratos since December 2024 — the platform added browser-in-the-browser (BitB) fake login windows in November 2025 and Cloudflare Turnstile anti-bot challenges to blunt automated analysis and takedown, and ran an estimated 15,000 phishing campaigns a month across 200+ servers for roughly 1,800 subscribers (Trend Micro, 2026-07-22). Authorities seized the infrastructure and arrested the platform's developer/technical administrator in Indonesia (BKA, 2026-07-20).

Over 1,800 criminal subscribers had rented access to Kratos and used it to run an estimated 15,000 phishing campaigns a month.

Trend Micro Research 2026-07-22

bedeutender Ermittlungserfolg gegen eine der weltweit gefährlichsten Phishing-as-a-Service-Gruppierung

Bundeskriminalamt (BKA)
threat24 Jul 04:36Zmulti-sourceOpen finding ↗