Kratos PhaaS Takedown: Fake Microsoft Logins

The Register Security · High sophistication
Last updated July 30, 2026

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help criminals bypass multi-factor authentication (MFA). Reporting also links the kit to tax-season lures (fake W-2 forms) and other common cloud-service themes like SharePoint and OneDrive.

How the attack worked

Kratos was a phishing-as-a-service kit that gave criminals with little technical skill access to convincing, Microsoft-themed fake login pages. Victims who clicked a link and entered credentials had both their password and session cookie captured. Because the session cookie was stolen, attackers could potentially reuse an active login session, effectively sidestepping the extra protection multi-factor authentication is supposed to provide.

Law enforcement action, led by German authorities, disrupted the infrastructure behind the kit, reportedly taking down more than 200 servers, and authorities allege the developer or technical administrator was arrested in Indonesia. Open-source reporting also links Kratos to other kit names and connects it to a wide set of lure themes beyond Microsoft, including SharePoint, OneDrive, Microsoft Forms, Adobe, and Canva.

Why it succeeded

The kit's success came from believability and reach. It packaged convincing Microsoft sign-in pages that could be deployed at scale, and it reused everyday business workflows, like opening a shared document or reviewing a tax form, as the entry point. Because these are routine actions employees perform constantly, the phishing pages blended into normal work patterns rather than standing out as unusual requests.

Seasonal timing added pressure. Fake W-2 tax form lures targeted US citizens during tax season, when people expect to receive and act on tax documents quickly, making them less likely to scrutinize a sign-in prompt closely.

What to watch for

  • An unexpected prompt to sign in to Microsoft 365 in order to view a shared document
  • A login page that looks Microsoft-branded but sits on an unfamiliar domain or URL
  • Tax documents, like W-2 forms, arriving unexpectedly by email link, especially during tax season
  • Sign-in requests tied to SharePoint, OneDrive, Microsoft Forms, or similar tools that don't match how your organization normally shares files
  • Any sense of urgency pushing you to log in quickly without verifying the sender

How to build resistance

Organizations across manufacturing, retail, healthcare, and other affected sectors should reinforce a few habits. Employees should treat unexpected Microsoft sign-in prompts as suspicious and verify both the sender and the link before entering credentials. Because MFA is not a guarantee against session-cookie theft, unusual sign-in pages or prompts should be reported immediately rather than dismissed.

HR, payroll, and finance teams handling tax-season documents and other administrative requests should be especially cautious of links that ask for a login to view a form. Since attackers reuse trusted business tools like SharePoint and OneDrive as lures, document-sharing requests are best verified through a separate, known communication channel before clicking through and signing in.

Key findings

  • Law enforcement said Kratos was a major phishing-as-a-service kit and disrupted its infrastructure, including “more than 200 servers.”
  • Authorities allege the kit’s developer/technical administrator was arrested in Indonesia.
  • Kratos enabled “low-skill cybercrims” to run convincing Microsoft-themed phishing pages that stole passwords and session cookies, enabling MFA bypass.
  • Open-source reporting ties Kratos to other names (SneakyLog / Sneaky 2FA) and to multiple lure themes (SharePoint, OneDrive, Microsoft Forms, Adobe, Canva, etc.).
  • Victims were targeted “across more than 30 countries,” with heavy focus on the US and Europe; manufacturing, retail, and healthcare were highlighted as US targets.

Who’s being targeted

  • Commonly targeted roles: All employees, HR, Payroll, Finance, IT/Helpdesk, Operations.
  • Affected industries: Manufacturing, Retail, Healthcare, Industrial organizations, Legal services (law firms), Education (schools, polytechnic institutions), Small and medium-sized businesses (SMBs).
  • Attack channels: email, website.
  • Impersonated: Microsoft (login) / SharePoint or OneDrive, HR/Payroll (internal) and Microsoft (login).

Red flags to watch for

  • Unexpected request to sign in to view a document
  • Login page feels “Microsoft-themed” but the URL/domain is unfamiliar
  • Any request that results in credentials/session being captured (risk of account takeover/MFA bypass)
  • Tax documents arriving unexpectedly by email link
  • Pressure to act quickly during “tax season”
  • A sign-in prompt that doesn’t match normal HR/payroll workflows
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was Kratos?

Kratos was a phishing-as-a-service kit that let low-skill criminals run convincing Microsoft-themed phishing pages to steal passwords and session cookies from victims.

How did Kratos bypass multi-factor authentication?

By stealing session cookies alongside passwords, attackers could hijack an already-authenticated session rather than needing to defeat MFA directly.

What lures did Kratos use?

Reporting ties Kratos to fake W-2 tax forms and lure themes based on SharePoint, OneDrive, Microsoft Forms, Adobe, and Canva sign-in pages.

Who was affected by Kratos phishing campaigns?

Victims were targeted across more than 30 countries with a heavy focus on the US and Europe, and manufacturing, retail, and healthcare were highlighted as US targets.

Read the video transcript

You get an email: “New W-2 form available” or “SharePoint file shared with you.” Looks normal, Microsoft logo and all. Behind the scenes, a kit called Kratos, also known as SneakyLog, was helping low-skill scammers spin up fake Microsoft login pages on more than 200 servers, built to steal your password and even your session cookie to bypass MFA. Here’s the trick: you click the W-2 or OneDrive link, a very Microsoft-looking sign-in pops up, but the URL is something like 'login-secure-docs[.]com' instead of microsoft.com or your usual company SSO page. If a Microsoft sign-in page appears from an email link and the URL isn’t microsoft.com or your normal SSO, stop and report it to IT, do not enter your password.

Similar attacks

Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

July 24, 2026