CyberSecurityBoardThreat Intel · CVEs · Products
Malware

SneakyLog: Microsoft-Tracked Phishing-as-a-Service Platform

July 22, 2026

SneakyLog is the name used by Microsoft Threat Intelligence for the Kratos phishing kit. It has been active since early 2025, targeting Microsoft 365 credentials and session cookies to bypass MFA. Microsoft has tracked campaigns using tax-themed emails with QR codes to lure victims.