# Kali365 PhaaS operators

> As of 2026-07-22, Kali365 PhaaS operators is a Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer)-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. Also known as Kali365, Kali 365, K365, Storm-1755. ATT&CK coverage spans 46 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1078.004 (Cloud Accounts), T1087.004 (Cloud Account), T1098.005 (Device Registration).

- **Nation:** Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer)
- **Tracked threats:** 2
- **Categories:** PHISHING
- **Also known as:** Kali365, Kali 365, K365, Storm-1755, Midnight Blizzard, APT29
- **As of:** 2026-07-22

## ATT&CK techniques observed

46 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (9), Collection (5), Discovery (5), Initial Access (5), Persistence (5), Command and Control (3).

- [T1078.004](https://intel.threadlinqs.com/technique/T1078.004) Cloud Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1087.004](https://intel.threadlinqs.com/technique/T1087.004) Cloud Account — Discovery — observed in 2 of 2 tracked threats
- [T1098.005](https://intel.threadlinqs.com/technique/T1098.005) Device Registration — Persistence — observed in 2 of 2 tracked threats
- [T1114.002](https://intel.threadlinqs.com/technique/T1114.002) Remote Email Collection — Collection — observed in 2 of 2 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 2 of 2 tracked threats
- [T1534](https://intel.threadlinqs.com/technique/T1534) Internal Spearphishing — Lateral Movement — observed in 2 of 2 tracked threats
- [T1537](https://intel.threadlinqs.com/technique/T1537) Transfer Data to Cloud Account — Exfiltration — observed in 2 of 2 tracked threats
- [T1550.001](https://intel.threadlinqs.com/technique/T1550.001) Application Access Token — Lateral Movement — observed in 2 of 2 tracked threats
- [T1566.002](https://intel.threadlinqs.com/technique/T1566.002) Spearphishing Link — Initial Access — observed in 2 of 2 tracked threats
- [T1587.001](https://intel.threadlinqs.com/technique/T1587.001) Malware — Resource Development — observed in 2 of 2 tracked threats
- [T1069.003](https://intel.threadlinqs.com/technique/T1069.003) Cloud Groups — Discovery — observed in 1 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 1 of 2 tracked threats
- [T1087.003](https://attack.mitre.org/techniques/T1087/003/) Email Account — Discovery — observed in 1 of 2 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 1 of 2 tracked threats
- [T1098.002](https://attack.mitre.org/techniques/T1098/002/) Additional Email Delegate Permissions — Persistence — observed in 1 of 2 tracked threats

## Tracked threats

- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — HIGH
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)](https://intel.threadlinqs.com/threat/TL-2026-0560) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators
