Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)

Kali365 (K365) PhaaS Expansion (TL-2026-0693), also tracked as K365, is a high-severity phishing campaign, first published 2026-06-06. It is attributed to Kali365 operator with medium confidence, affects Microsoft Entra ID / Microsoft 365 (OAuth 2.0 device-authorization, maps to 13 MITRE ATT&CK techniques (T1056.003, T1102, T1111), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0693

Threat ID
TL-2026-0693
Also known as
K365, Kali365 PhaaS
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-06-06
Last reviewed
2026-06-06
Attribution
Kali365 operator
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
government, technology, financial, professional services, consumer, telecommunications
Target regions
Russia, North America, Europe
Detection rules
9
Indicators of compromise
20

Malware and tooling in Kali365 (K365) PhaaS Expansion

Malware and tooling: @NovosibyrskyMoneyBot, K365 Control

Kali365 (K365), an FBI-flagged phishing-as-a-service operation first documented in April 2026 abusing Microsoft's OAuth 2.0 device-authorization grant for Entra ID token theft, has expanded into a multi-brand operation. Arctic Wolf Labs documented a 126-host cluster (observed 6-27 May 2026) impersonating Microsoft Outlook/Live, Okta SSO, Xerox DocuShare, AWS, LiveDrive, GMX, Mail.ru, Yandex Disk, Odnoklassniki, and Russia's state MAX Messenger, all backed by a live token-capture C2 panel at panel.securehubcloud.com.

How Kali365 (K365) PhaaS Expansion works

Kali365 (K365) is a subscription phishing-as-a-service (PhaaS) kit (~$250/month, Bitcoin, sold via Telegram) operated by a single actor cluster that Arctic Wolf Labs assesses is the same operator behind the April 2026 OneDrive/SharePoint device-code phishing campaign (FBI-flagged; Arctic Wolf 'Token Bingo' report, 24 April 2026). The June 2026 reporting documents a material escalation: a 126-host phishing cluster (observation window 6-27 May 2026) that has broadened from Microsoft 365 to Okta SSO, Xerox DocuShare, AWS-style endpoints (vpce./apm. naming), LiveDrive, GMX/1&1 Mail, and a heavy emphasis on Russian consumer platforms (Mail.ru, Yandex Disk/yadi.sk, Odnoklassniki/ok.ru, and MAX Messenger).

The core technique against Microsoft is abuse of the OAuth 2.0 Device Authorization Grant (RFC 8628), a flow designed for input-constrained devices such as smart TVs and printers. The operator initiates a device-code request against a malicious first-party-styled application and receives a legitimate user_code from Microsoft. That code (e.g. 'SHQ748WLY', hardcoded per-delivery into the phishing HTML) is embedded into a lure page impersonating a secure-document portal ('Preparing your secure document...' loader). When the victim authenticates the code at the genuine microsoft.com/devicelogin endpoint and completes MFA, Microsoft issues OAuth access and refresh tokens directly to the attacker's application — bypassing MFA entirely without ever capturing the victim's password or second factor. The phishing page polls the C2 (panel.securehubcloud.com) every 3 seconds for capture status using same-origin fetch() to sibling C2 paths, document.open()/document.write() DOM swapping, and setTimeout-delayed loaders.

The MAX Messenger account-takeover flow (hosted on greatness-marketing.top, same 'K365 Control' branding) uses a fake prize-claim verification lure restricted to Russian (+7) numbers ('Для входа нужен номер из России'). The victim enters their phone number, the real MAX backend sends a genuine OTP via SMS/push, the victim enters the 6-digit OTP into a grid, and is then prompted for an optional 2FA password ('Пароль 2FA, если есть'). Phone number, OTP, and 2FA password are exfiltrated in real time to a Telegram bot (@NovosibyrskyMoneyBot / sova_novosibirsk_bot, token 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg, chat -5035652280). Compromised MAX accounts expose messages, media, and the full contact list, enabling worm-like propagation across Russia's 110M+ MAX user base.

Infrastructure is short-lived and resilient: Cloudflare Workers disposable subdomains (e.g. open-box-rpps.jeff-1fd.workers.dev) as primary delivery, a shared cPanel host (attachedfile.com, 39+ malicious subdomains serving an identical kit), Cloudflare fronting (172.67.156.83, 104.21.32.229, AS13335), median domain lifespan of days, a stable TLS certificate fingerprint (SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a), a recurring HTTP banner hash (febb622cd9eeb5c8860dcef4cbfd4b74), and affiliate/session telemetry (hardcoded SID 2091010, tracking pixel tk.mowell.tech). The C2 footer exposes 'Renewal' links consistent with a subscription PhaaS economic model. The kit advertises AI-generated lures and automated multi-brand campaign templates. This threat is a follow-on to previously tracked TL-2026-0560 (Kali365 M365 device-code phishing).

MITRE ATT&CK techniques used in TL-2026-0693

Collection

T1056.003 Web Portal Capture

Command and Control

T1102 Web Service

Credential Access

T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1583.006 Web Services; T1587 Develop Capabilities; T1608.005 Link Target

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Kali365 (K365) PhaaS Expansion

  • Microsoft — Entra ID / Microsoft 365 (OAuth 2.0 device-authorization grant)
    Vulnerable versions: all tenants without device-code Conditional Access
  • Okta — Okta SSO (credential phishing impersonation)
    Vulnerable versions: N/A - brand impersonation
  • Xerox — DocuShare (credential phishing impersonation)
    Vulnerable versions: N/A - brand impersonation
  • Amazon — AWS (endpoint-name impersonation: vpce./apm.)
    Vulnerable versions: N/A - brand impersonation
  • VK / Russian Government — MAX Messenger (OTP + 2FA phishing takeover)
    Vulnerable versions: all accounts

Remediation for Kali365 (K365) PhaaS Expansion

Immediate actions

  • Block panel.securehubcloud.com, api.securehubcloud.com, boss.securehubcloud.com, greatness-marketing.top, attachedfile.com (and *.attachedfile.com), tk.mowell.tech, and the open-box-rpps.jeff-1fd.workers.dev host at web/egress proxies and DNS
  • Block Cloudflare-fronted C2 IPs 172.67.156.83 and 104.21.32.229 where feasible
  • Block outbound Telegram Bot API (api.telegram.org) from corporate networks; hunt for bot token 8535071077 and chat -5035652280
  • Hunt mailflow and proxy logs for 'Preparing your secure document' lure strings and microsoft.com/devicelogin referrals from external links

Workarounds

  • Disable device-code flow for users/groups that have no smart-device authentication need
  • Restrict registration of new enterprise/multi-tenant OAuth applications

Longer-term hardening

  • Enforce Conditional Access policies that block or tightly scope the OAuth 2.0 device-code authorization flow (Entra ID 'Authentication flows' policy)
  • Deploy phishing-resistant FIDO2/WebAuthn MFA to defeat device-code token theft
  • Enable token protection / continuous access evaluation (CAE) and monitor for anomalous refresh-token redemption and impossible-travel sign-ins
  • User awareness: never approve a device code you did not personally initiate

Weaknesses (CWE) in Kali365 (K365) PhaaS Expansion

CWE-1390, CWE-287, CWE-308

Timeline of Kali365 (K365) PhaaS Expansion

  • MAX Messenger, Russia's state-backed national messenger, launched (110M+ registered users by April 2026) - later targeted by Kali365 account-takeover kit.
  • Arctic Wolf publishes 'Token Bingo: Don't Let Your Code Be the Winner', documenting the original Kali365 Microsoft OAuth device-code phishing campaign (tracked as TL-2026-0560).
  • FBI flags the Kali365 phishing kit (PSA reference) following active device-code token-theft campaigns.
  • Start of Arctic Wolf observation window for the expanded 126-host Kali365 cluster.
  • End of Arctic Wolf observation window; 126 distinct hosts sharing the banner fingerprint identified, median domain lifespan of days.
  • Arctic Wolf Labs publishes expansion report documenting Kali365 spread to Okta, AWS, Xerox DocuShare, LiveDrive, GMX, Mail.ru, Yandex, Odnoklassniki, and MAX Messenger plus live C2 panel.
  • Threadlinqs Intelligence opens TL-2026-0693 to track the expanded Kali365 PhaaS operation with dedicated IOCs and detections.

Sources cited for Kali365 (K365) PhaaS Expansion

Threats related to Kali365 (K365) PhaaS Expansion

Detection coverage for TL-2026-0693

As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0693 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats