# Kali365

> As of 2026-09-12, Kali365 is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning phishing. ATT&CK coverage spans 65 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1583 (Acquire Infrastructure), T1534 (Internal Spearphishing).

- **Tracked threats:** 5
- **Categories:** PHISHING
- **As of:** 2026-09-12

## ATT&CK techniques observed

65 techniques observed across 5 of 5 tracked threats. Tactics: Resource Development (11), Credential Access (10), Initial Access (7), Collection (6), Discovery (5), Persistence (5).

- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 5 of 5 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 4 of 5 tracked threats
- [T1534](https://intel.threadlinqs.com/technique/T1534) Internal Spearphishing — Lateral Movement — observed in 3 of 5 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 3 of 5 tracked threats
- [T1566.002](https://intel.threadlinqs.com/technique/T1566.002) Spearphishing Link — Initial Access — observed in 3 of 5 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 5 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 2 of 5 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 2 of 5 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 5 tracked threats
- [T1114](https://intel.threadlinqs.com/technique/T1114) Email Collection — Collection — observed in 2 of 5 tracked threats
- [T1114.002](https://intel.threadlinqs.com/technique/T1114.002) Remote Email Collection — Collection — observed in 2 of 5 tracked threats
- [T1137.005](https://attack.mitre.org/techniques/T1137/005/) Outlook Rules — Persistence — observed in 2 of 5 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 2 of 5 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 2 of 5 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 2 of 5 tracked threats

## Tracked threats

- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — HIGH
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — HIGH
- [Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365)](https://intel.threadlinqs.com/threat/TL-2026-0943) — HIGH
- [Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)](https://intel.threadlinqs.com/threat/TL-2026-0693) — HIGH
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)](https://intel.threadlinqs.com/threat/TL-2026-0560) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Kali365
