Activity timeline
Kali365 PhaaS operators appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.
ATT&CK techniques observed
- T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 2 tracked threats
- T1087.004 Cloud Account — Discoveryobserved in 2 of 2 tracked threats
- T1098.005 Device Registration — Persistenceobserved in 2 of 2 tracked threats
- T1114.002 Remote Email Collection — Collectionobserved in 2 of 2 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 2 of 2 tracked threats
- T1534 Internal Spearphishing — Lateral Movementobserved in 2 of 2 tracked threats
- T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 2 of 2 tracked threats
- T1550.001 Application Access Token — Lateral Movementobserved in 2 of 2 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 2 of 2 tracked threats
- T1587.001 Malware — Resource Developmentobserved in 2 of 2 tracked threats
- T1069.003 Cloud Groups — Discoveryobserved in 1 of 2 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
- T1087.003 Email Account — Discoveryobserved in 1 of 2 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 1 of 2 tracked threats
- T1098.002 Additional Email Delegate Permissions — Persistenceobserved in 1 of 2 tracked threats