Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

Kali365

As of 2026-09-12, Kali365 is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning phishing. ATT&CK coverage spans 65 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1583 (Acquire Infrastructure), T1534 (Internal Spearphishing).

Tracked threats
55 high
First seen
2026-05-22
Last seen
2026-09-12
ATT&CK techniques
65across 5 of 5 threats
Related CVEs
0None referenced
5 tracked threat(s) · Categories: PHISHING

Activity timeline

Kali365 appears in 5 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

65 techniques observed across 5 of 5 tracked threats · Resource Development (11), Credential Access (10), Initial Access (7), Collection (6), Discovery (5), Persistence (5)
  • T1528 Steal Application Access Token — Credential Accessobserved in 5 of 5 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 4 of 5 tracked threats
  • T1534 Internal Spearphishing — Lateral Movementobserved in 3 of 5 tracked threats
  • T1566 Phishing — Initial Accessobserved in 3 of 5 tracked threats
  • T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 5 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 5 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 2 of 5 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 2 of 5 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 5 tracked threats
  • T1114 Email Collection — Collectionobserved in 2 of 5 tracked threats
  • T1114.002 Remote Email Collection — Collectionobserved in 2 of 5 tracked threats
  • T1137.005 Outlook Rules — Persistenceobserved in 2 of 5 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 2 of 5 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 2 of 5 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 2 of 5 tracked threats

Tracked threats