Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
Kali365 (K365) PhaaS Expansion (TL-2026-0693), also tracked as K365, is a high-severity phishing campaign, first published 2026-06-06. It is attributed to Kali365 operator with medium confidence, affects Microsoft Entra ID / Microsoft 365 (OAuth 2.0 device-authorization, maps to 13 MITRE ATT&CK techniques (T1056.003, T1102, T1111), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0693
- Threat ID
- TL-2026-0693
- Also known as
- K365, Kali365 PhaaS
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-06-06
- Last reviewed
- 2026-06-06
- Attribution
- Kali365 operator
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- government, technology, financial, professional services, consumer, telecommunications
- Target regions
- Russia, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Kali365 (K365) PhaaS Expansion
Malware and tooling: @NovosibyrskyMoneyBot, K365 Control
Kali365 (K365), an FBI-flagged phishing-as-a-service operation first documented in April 2026 abusing Microsoft's OAuth 2.0 device-authorization grant for Entra ID token theft, has expanded into a multi-brand operation. Arctic Wolf Labs documented a 126-host cluster (observed 6-27 May 2026) impersonating Microsoft Outlook/Live, Okta SSO, Xerox DocuShare, AWS, LiveDrive, GMX, Mail.ru, Yandex Disk, Odnoklassniki, and Russia's state MAX Messenger, all backed by a live token-capture C2 panel at panel.securehubcloud.com.
How Kali365 (K365) PhaaS Expansion works
Kali365 (K365) is a subscription phishing-as-a-service (PhaaS) kit (~$250/month, Bitcoin, sold via Telegram) operated by a single actor cluster that Arctic Wolf Labs assesses is the same operator behind the April 2026 OneDrive/SharePoint device-code phishing campaign (FBI-flagged; Arctic Wolf 'Token Bingo' report, 24 April 2026). The June 2026 reporting documents a material escalation: a 126-host phishing cluster (observation window 6-27 May 2026) that has broadened from Microsoft 365 to Okta SSO, Xerox DocuShare, AWS-style endpoints (vpce./apm. naming), LiveDrive, GMX/1&1 Mail, and a heavy emphasis on Russian consumer platforms (Mail.ru, Yandex Disk/yadi.sk, Odnoklassniki/ok.ru, and MAX Messenger).
The core technique against Microsoft is abuse of the OAuth 2.0 Device Authorization Grant (RFC 8628), a flow designed for input-constrained devices such as smart TVs and printers. The operator initiates a device-code request against a malicious first-party-styled application and receives a legitimate user_code from Microsoft. That code (e.g. 'SHQ748WLY', hardcoded per-delivery into the phishing HTML) is embedded into a lure page impersonating a secure-document portal ('Preparing your secure document...' loader). When the victim authenticates the code at the genuine microsoft.com/devicelogin endpoint and completes MFA, Microsoft issues OAuth access and refresh tokens directly to the attacker's application — bypassing MFA entirely without ever capturing the victim's password or second factor. The phishing page polls the C2 (panel.securehubcloud.com) every 3 seconds for capture status using same-origin fetch() to sibling C2 paths, document.open()/document.write() DOM swapping, and setTimeout-delayed loaders.
The MAX Messenger account-takeover flow (hosted on greatness-marketing.top, same 'K365 Control' branding) uses a fake prize-claim verification lure restricted to Russian (+7) numbers ('Для входа нужен номер из России'). The victim enters their phone number, the real MAX backend sends a genuine OTP via SMS/push, the victim enters the 6-digit OTP into a grid, and is then prompted for an optional 2FA password ('Пароль 2FA, если есть'). Phone number, OTP, and 2FA password are exfiltrated in real time to a Telegram bot (@NovosibyrskyMoneyBot / sova_novosibirsk_bot, token 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg, chat -5035652280). Compromised MAX accounts expose messages, media, and the full contact list, enabling worm-like propagation across Russia's 110M+ MAX user base.
Infrastructure is short-lived and resilient: Cloudflare Workers disposable subdomains (e.g. open-box-rpps.jeff-1fd.workers.dev) as primary delivery, a shared cPanel host (attachedfile.com, 39+ malicious subdomains serving an identical kit), Cloudflare fronting (172.67.156.83, 104.21.32.229, AS13335), median domain lifespan of days, a stable TLS certificate fingerprint (SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a), a recurring HTTP banner hash (febb622cd9eeb5c8860dcef4cbfd4b74), and affiliate/session telemetry (hardcoded SID 2091010, tracking pixel tk.mowell.tech). The C2 footer exposes 'Renewal' links consistent with a subscription PhaaS economic model. The kit advertises AI-generated lures and automated multi-brand campaign templates. This threat is a follow-on to previously tracked TL-2026-0560 (Kali365 M365 device-code phishing).
MITRE ATT&CK techniques used in TL-2026-0693
Collection
Command and Control
Credential Access
T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation
Execution
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1583.006 Web Services; T1587 Develop Capabilities; T1608.005 Link Target
Defense Evasion
Affected products and versions in Kali365 (K365) PhaaS Expansion
- Microsoft — Entra ID / Microsoft 365 (OAuth 2.0 device-authorization grant)
Vulnerable versions: all tenants without device-code Conditional Access - Okta — Okta SSO (credential phishing impersonation)
Vulnerable versions: N/A - brand impersonation - Xerox — DocuShare (credential phishing impersonation)
Vulnerable versions: N/A - brand impersonation - Amazon — AWS (endpoint-name impersonation: vpce./apm.)
Vulnerable versions: N/A - brand impersonation - VK / Russian Government — MAX Messenger (OTP + 2FA phishing takeover)
Vulnerable versions: all accounts
Remediation for Kali365 (K365) PhaaS Expansion
Immediate actions
- Block panel.securehubcloud.com, api.securehubcloud.com, boss.securehubcloud.com, greatness-marketing.top, attachedfile.com (and *.attachedfile.com), tk.mowell.tech, and the open-box-rpps.jeff-1fd.workers.dev host at web/egress proxies and DNS
- Block Cloudflare-fronted C2 IPs 172.67.156.83 and 104.21.32.229 where feasible
- Block outbound Telegram Bot API (api.telegram.org) from corporate networks; hunt for bot token 8535071077 and chat -5035652280
- Hunt mailflow and proxy logs for 'Preparing your secure document' lure strings and microsoft.com/devicelogin referrals from external links
Workarounds
- Disable device-code flow for users/groups that have no smart-device authentication need
- Restrict registration of new enterprise/multi-tenant OAuth applications
Longer-term hardening
- Enforce Conditional Access policies that block or tightly scope the OAuth 2.0 device-code authorization flow (Entra ID 'Authentication flows' policy)
- Deploy phishing-resistant FIDO2/WebAuthn MFA to defeat device-code token theft
- Enable token protection / continuous access evaluation (CAE) and monitor for anomalous refresh-token redemption and impossible-travel sign-ins
- User awareness: never approve a device code you did not personally initiate
Weaknesses (CWE) in Kali365 (K365) PhaaS Expansion
CWE-1390, CWE-287, CWE-308
Timeline of Kali365 (K365) PhaaS Expansion
- MAX Messenger, Russia's state-backed national messenger, launched (110M+ registered users by April 2026) - later targeted by Kali365 account-takeover kit.
- Arctic Wolf publishes 'Token Bingo: Don't Let Your Code Be the Winner', documenting the original Kali365 Microsoft OAuth device-code phishing campaign (tracked as TL-2026-0560).
- FBI flags the Kali365 phishing kit (PSA reference) following active device-code token-theft campaigns.
- Start of Arctic Wolf observation window for the expanded 126-host Kali365 cluster.
- End of Arctic Wolf observation window; 126 distinct hosts sharing the banner fingerprint identified, median domain lifespan of days.
- Arctic Wolf Labs publishes expansion report documenting Kali365 spread to Okta, AWS, Xerox DocuShare, LiveDrive, GMX, Mail.ru, Yandex, Odnoklassniki, and MAX Messenger plus live C2 panel.
- Threadlinqs Intelligence opens TL-2026-0693 to track the expanded Kali365 PhaaS operation with dedicated IOCs and detections.
Sources cited for Kali365 (K365) PhaaS Expansion
- From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
- Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger
- FBI-Flagged Phishing Kit Kali365 Expands Its Reach
- Token Bingo: Don't Let Your Code Be the Winner (original Kali365 device-code report)
- Microsoft OAuth 2.0 Device Authorization Grant (RFC 8628) abuse - background
Threats related to Kali365 (K365) PhaaS Expansion
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU)
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)
- Zscaler ThreatLabz 2026 Phishing Report: Volume Falls 20% as AI Trades Mass Spam for Targeted, Higher-Conversion Credential & Session-Theft Campaigns
- O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack Enterprise Accounts
- Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public Sector
Detection coverage for TL-2026-0693
As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0693 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.