Threadlinqs IntelligenceStart free

Threat actorUnknown (criminal PhaaS; Russian-aligned APT29 observed as customer)Tracked since 2026-05

Kali365 PhaaS operators

Also known as:Kali365Kali 365K365Storm-1755Midnight BlizzardAPT29

As of 2026-07-22, Kali365 PhaaS operators is a Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer)-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. Also known as Kali365, Kali 365, K365, Storm-1755. ATT&CK coverage spans 46 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1078.004 (Cloud Accounts), T1087.004 (Cloud Account), T1098.005 (Device Registration).

Tracked threats
22 high
First seen
2026-05-22
Last seen
2026-07-22
ATT&CK techniques
46across 2 of 2 threats
Related CVEs
0None referenced
Attribution
Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer)Nation or origin
Nation: Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer) · 2 tracked threat(s) · Categories: PHISHING

Activity timeline

Kali365 PhaaS operators appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.

ATT&CK techniques observed

46 techniques observed across 2 of 2 tracked threats · Resource Development (9), Collection (5), Discovery (5), Initial Access (5), Persistence (5), Command and Control (3)
  • T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 2 tracked threats
  • T1087.004 Cloud Account — Discoveryobserved in 2 of 2 tracked threats
  • T1098.005 Device Registration — Persistenceobserved in 2 of 2 tracked threats
  • T1114.002 Remote Email Collection — Collectionobserved in 2 of 2 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 2 of 2 tracked threats
  • T1534 Internal Spearphishing — Lateral Movementobserved in 2 of 2 tracked threats
  • T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 2 of 2 tracked threats
  • T1550.001 Application Access Token — Lateral Movementobserved in 2 of 2 tracked threats
  • T1566.002 Spearphishing Link — Initial Accessobserved in 2 of 2 tracked threats
  • T1587.001 Malware — Resource Developmentobserved in 2 of 2 tracked threats
  • T1069.003 Cloud Groups — Discoveryobserved in 1 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
  • T1087.003 Email Account — Discoveryobserved in 1 of 2 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 1 of 2 tracked threats
  • T1098.002 Additional Email Delegate Permissions — Persistenceobserved in 1 of 2 tracked threats

Tracked threats