Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. (Citation: Huntress Kali365 Device Code June 2026) Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) Kali365 PHaaS was first observed in April 2026.(Citation: Artic Wolf Labs Kali365 Device Code April 2026) Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.(Citation: Huntress Kali365 Device Code June 2026)
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
What I discovered was that this was a fairly new PhaaS kit known as Kali365. Similar to our reporting on EvilTokens earlier this year, this phishing kit uses the device authentication code flow to trick users into letting them into environments, and keeping access even if MFA is used and passwords are changed post-compromise.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims are persuaded to enter an attacker-provided device code and complete authentication, unknowingly authorizing an attacker-controlled application or session.
“If that role includes Global Administrator, the amber Admin button appears immediately. One click. Full inbox access.”
“Victims are steered to the genuine login.microsoft.com/device page and approve an attacker-initiated device session.”
In a typical attack executed in ANY.RUN Sandbox, the victim receives a phishing message containing a lure, often themed around SharePoint or a document-sharing request.
Victims are persuaded to enter an attacker-provided device code and complete authentication, unknowingly authorizing an attacker-controlled application or session.
Victims are persuaded to enter an attacker-provided device code and complete authentication, unknowingly authorizing an attacker-controlled application or session.
Victims are persuaded to enter an attacker-provided device code and complete authentication, unknowingly authorizing an attacker-controlled application or session.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
The platform reportedly offers AI-generated phishing emails, automated campaign management, victim tracking dashboards, and OAuth token capture capabilities.
Since attackers are harvesting session cookies and tokens, they inherit fully authenticated identities inside Microsoft 365 rather than simply stealing passwords.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
At the core of this operation is adversary in the middle phishing that turns Outlook itself into a trusted relay for Microsoft 365 session theft.
Once authentication is approved, the attacker receives OAuth tokens connected to the device code flow. Access tokens enable temporary access to approved resources, while refresh tokens may allow attackers to request new access tokens and maintain access over time.
221 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing toolkit supporting device-code phishing and adversary-in-the-middle attacks. It dynamically generates device codes when victims open a lure. Its OctoLink Live component converts stolen refresh tokens into authenticated browser sessions.
Referenced only as a comparable phishing kit focused on stealing session tokens or OAuth access tokens.
A device code phishing tool mentioned for comparison with GraphSpy.
Phishing-as-a-Service platform that abuses Microsoft OAuth device-code authentication flows. It sends convincing document-sharing lures, induces victims to enter attacker-provided device codes in a legitimate Microsoft workflow, and captures OAuth access tokens after victims authorize access. Reported capabilities include AI-generated phishing emails, campaign automation, victim-tracking dashboards, and token capture.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.