SneakyLog is the name used by Microsoft Threat Intelligence for the Kratos phishing kit. It has been active since early 2025, targeting Microsoft 365 credentials and session cookies to bypass MFA. Microsoft has tracked campaigns using tax-themed emails with QR codes to lure victims.