Kratos is a phishing-as-a-service (PhaaS) operation and associated criminal group focused on large-scale theft of Microsoft 365 credentials and authenticated sessions. The service has also been tracked under the names SneakyLog and as an evolution or rebrand of Sneaky2FA. It provided subscribers with a turnkey phishing toolkit that enabled less technically skilled criminals to run high-volume campaigns against Microsoft 365 users, primarily through convincing fake Microsoft sign-in workflows and adversary-in-the-middle phishing. Kratos specialized in bypassing multi-factor authentication by relaying live authentication sessions and capturing both credentials and session cookies or tokens. Reported operating modes included standard credential-harvesting pages as well as reverse-proxy infrastructure that intercepted authenticated sessions in real time. The platform also used trusted-cloud redirect chains, document-sharing and DocuSign-style lures, antibot protections, and browser-in-the-browser style login windows to increase plausibility and evade automated defenses and user scrutiny. Kratos was distributed through a subscription model and managed through web and Telegram-based interfaces. The operation was used at industrial scale, with reporting attributing roughly 15,000 phishing campaigns per month to more than 1,800 customers and victims across more than 30 countries, especially in Europe and the United States. Kratos infrastructure was linked to broad phishing activity observed in 2026, including campaigns delivering HTML attachments and credential-theft flows associated with other PhaaS ecosystems such as Tycoon2FA and EvilTokens. Law enforcement action in 2026 significantly disrupted the operation. German authorities, with U.S. support and an arrest in Indonesia, dismantled core Kratos infrastructure in Operation Olympus Blade, seizing or disabling more than 200 servers. Kratos is best characterized as a financially motivated cybercriminal service provider enabling credential theft and session hijacking at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-service operations using trusted cloud redirects and DocuSign-style lures to steal Microsoft 365 credentials and gain cloud access.
PhaaS-платформа, использовавшаяся для массовых фишинговых кампаний против пользователей Microsoft 365, включая adversary-in-the-middle атаки для перехвата учетных данных и сессионных cookie с обходом MFA.
A phishing-as-a-service operation that provided subscribers with a toolkit to create and manage Microsoft-themed phishing pages for large-scale credential theft. It was leased to criminal customers to run phishing campaigns at scale.
Operators ran a phishing-as-a-service platform used at scale to steal Microsoft 365 credentials, enabling more than 1,800 criminal subscribers to conduct an estimated 15,000 phishing campaigns per month. The platform evolved from the Sneaky2FA adversary-in-the-middle phishing kit and supported large-volume credential theft across more than 30 countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.