Activity timeline
Kali365 appears in 5 tracked threats between and ; the busiest month was 2026-06 with 2 reports.
ATT&CK techniques observed
- T1528 Steal Application Access Token — Credential Accessobserved in 5 of 5 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 4 of 5 tracked threats
- T1534 Internal Spearphishing — Lateral Movementobserved in 3 of 5 tracked threats
- T1566 Phishing — Initial Accessobserved in 3 of 5 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 5 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 2 of 5 tracked threats
- T1087 Account Discovery — Discoveryobserved in 2 of 5 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 2 of 5 tracked threats
- T1102 Web Service — Command and Controlobserved in 2 of 5 tracked threats
- T1114 Email Collection — Collectionobserved in 2 of 5 tracked threats
- T1114.002 Remote Email Collection — Collectionobserved in 2 of 5 tracked threats
- T1137.005 Outlook Rules — Persistenceobserved in 2 of 5 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 2 of 5 tracked threats
- T1526 Cloud Service Discovery — Discoveryobserved in 2 of 5 tracked threats
- T1530 Data from Cloud Storage — Collectionobserved in 2 of 5 tracked threats
Tracked threats
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass CapabilityHIGH
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including PasskeysHIGH
- Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365)HIGH
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)HIGH
- Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)HIGH