ctipilot.ch
← Back to the live brief
NOTABLENATOA1threat

German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns

discovered 2026-07-24 04:36 UTCrun 2026-07-24T0409Z-intel2 sourcesmulti-source

Germany's Bundeskriminalamt (BKA), with the Frankfurt cybercrime prosecutor (ZIT), US law enforcement and Indonesian authorities, announced on 20 July 2026 the takedown of Kratos — a phishing-as-a-service (PhaaS) platform that sold subscribers a turnkey adversary-in-the-middle toolkit for generating convincing Microsoft 365 authentication pages (BKA, 2026-07-20). Per BKA and Trend Micro — which had tracked Sneaky2FA's evolution into Kratos since December 2024 — the platform added browser-in-the-browser (BitB) fake login windows in November 2025 and Cloudflare Turnstile anti-bot challenges to blunt automated analysis and takedown, and ran an estimated 15,000 phishing campaigns a month across 200+ servers for roughly 1,800 subscribers (Trend Micro, 2026-07-22). Authorities seized the infrastructure and arrested the platform's developer/technical administrator in Indonesia (BKA, 2026-07-20).

Over 1,800 criminal subscribers had rented access to Kratos and used it to run an estimated 15,000 phishing campaigns a month.

Trend Micro Research 2026-07-22

bedeutender Ermittlungserfolg gegen eine der weltweit gefährlichsten Phishing-as-a-Service-Gruppierung

Bundeskriminalamt (BKA)

ATT&CK mapping

3 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1566.002Phishing: Spearphishing Link

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1539Steal Web Session Cookie

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

overlap matrix · ATT&CK page ↗

T1557Adversary-in-the-Middle

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

overlap matrix · ATT&CK page ↗

Collection TA0009
T1557Adversary-in-the-Middle

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.