Last seven days
- First activity
- Jul 26, 2026
- Last activity
- Jul 26, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 10 hostnames
MITRE ATT&CK
Reporting
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits... Microsoft Threat Intelligence identifies the same kit as SneakyLog, a phishing-as-a-service platform it says has run credential-and-2FA theft against Microsoft 365 since at least early 2025.
German authorities, with support from the US and Indonesia, have successfully dismantled the primary infrastructure behind the Kratos phishing-as-a-service (PhaaS) kit, a tool described as one of the most dangerous and widespread on the market.
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.