German authorities, supported by the United States and Indonesia, dismantled the main infrastructure behind the Kratos phishing-as-a-service platform and reportedly neutralized more than 200 servers, while Indonesian authorities arrested the alleged developer and technical administrator. Investigators said the kit had been used by more than 1,800 criminal groups to launch roughly 15,000 phishing campaigns each month across more than 30 countries, primarily targeting organizations in the US and Europe. Also tracked as SneakyLog and Sneaky 2FA, Kratos was designed to steal credentials and session cookies through convincing Microsoft-themed phishing pages, enabling attackers to bypass multifactor authentication and compromise Microsoft 365 accounts.
Threat reporting had previously tied Kratos to broad phishing waves using lures themed around tax documents, IRS notices, CPA requests, and cryptocurrency tax forms, with victims spanning financial services, healthcare, education, retail, manufacturing, technology, law firms, schools, and SMBs. Campaigns impersonated services including SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and Adobe, and used evasive delivery methods such as QR codes, OneNote and Excel attachments, URL shorteners, cloud-hosted pages, and bot filtering. In one IRS-themed campaign, attackers targeted more than 29,000 users across 10,000 organizations and delivered a malicious ScreenConnect-based "Transcript Viewer" executable, showing how credential theft operations tied to Kratos also supported broader post-compromise access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
German authorities announced the takedown of the main infrastructure behind the Kratos phishing-as-a-service kit, with support from the United States and Indonesia. The operation reportedly neutralized more than 200 servers, and Indonesian authorities arrested the alleged developer and technical administrator.
Microsoft Threat Intelligence reported that early 2026 saw a seasonal increase in U.S. tax-themed phishing and malware activity targeting individuals, accountants, tax preparers, and organizations across multiple sectors. The campaigns used phishing kits including Energy365 and SneakyLog/Kratos and also abused remote monitoring and management tools such as ScreenConnect, SimpleHelp, and Datto.
On February 10, 2026, a large tax-themed phishing campaign impersonating the IRS targeted more than 29,000 users across 10,000 organizations. The campaign delivered a malicious ScreenConnect-based executable presented as a "Transcript Viewer."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcemicrosoft.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.