Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel) — Threadlinqs Intelligence
As of 2026-06-06, Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel) is a high-severity phishing threat attributed to Kali365 operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0693 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Kali365 operator · FINANCIAL
Kali365 (K365), an FBI-flagged phishing-as-a-service operation first documented in April 2026 abusing Microsoft's OAuth 2.0 device-authorization grant for Entra ID token theft, has expanded into a
Kali365 (K365) is a subscription phishing-as-a-service (PhaaS) kit (~$250/month, Bitcoin, sold via Telegram) operated by a single actor cluster that Arctic Wolf Labs assesses is the same operator behind the April 2026 OneDrive/SharePoint device-code phishing campaign (FBI-flagged; Arctic Wolf 'Token Bingo' report, 24 April 2026). The June 2026 reporting documents a material escalation: a 126-host phishing cluster (observation window 6-27 May 2026) that has broadened from Microsoft 365 to Okta SSO, Xerox DocuShare, AWS-style endpoints (vpce./apm. naming), LiveDrive, GMX/1&1 Mail, and a heavy emphasis on Russian consumer platforms (Mail.ru, Yandex Disk/yadi.sk, Odnoklassniki/ok.ru, and MAX Messenger).
The core technique against Microsoft is abuse of the OAuth 2.0 Device Authorization Grant (RFC 8628), a flow designed for input-constrained devices such as smart TVs and printers. The operator initiates a device-code request against a malicious first-party-styled application and receives a legitimate user_code from Microsoft. That code (e.g. 'SHQ748WLY', hardcoded per-delivery into the phishing HTML) is embedded into a lure page impersonating a secure-document portal ('Preparing your secure document...' loader). When the victim authenticates the code at the genuine microsoft.com/devicelogin endpoint and completes MFA, Microsoft issues OAuth access and refresh tokens directly to the attacker's application — bypassing MFA entirely without ever capturing the victim's password or second factor. The phishing page polls the C2 (panel.securehubcloud.com) every 3 seconds for capture status using same-origin fetch() to sibling C2 paths, document.open()/document.write() DOM swapping, and setTimeout-delayed loaders.
The MAX Messenger account-takeover flow (hosted on greatness-marketing.top, same 'K365 Control' branding) uses a fake prize-claim verification lure restricted to Russian (+7) numbers ('Для входа нужен номер из России'). The victim enters their phone number, the real MAX backend sends a genuine OTP via SMS/push, the victim enters the 6-digit OTP into a grid, and is then prompted for an optional 2FA password ('Пароль 2FA, если есть'). Phone number, OTP, and 2FA password are exfiltrated in real time to a Telegram bot (@NovosibyrskyMoneyBot / sova_novosibirsk_bot, token 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg, chat -5035652280). Compromised MAX accounts expose messages, media, and the full contact list, enabling worm-like propagation across Russia's 110M+ MAX user base.
Infrastructure is short-lived and resilient: Cloudflare Workers disposable subdomains (e.g. open-box-rpps.jeff-1fd.workers.dev) as primary delivery, a shared cPanel host (attachedfile.com, 39+ malicious subdomains serving an identical kit), Cloudflare fronting (172.67.156.83, 104.21.32.229, AS13335), median domain lifespan of days, a stable TLS certificate fingerprint (SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a), a recurring HTTP banner hash (febb622cd9eeb5c8860dcef4cbfd4b74), and affiliate/session telemetry (hardcoded SID 2091010, tracking pixel tk.mowell.tech). The C2 footer exposes 'Renewal' links consistent with a subscription PhaaS economic model. The kit advertises AI-generated lures and automated multi-brand campaign templates. This threat is a follow-on to previously tracked TL-2026-0560 (Kali365 M365 device-code phishing).
Weaknesses (CWE)
CWE-1390, CWE-287, CWE-308
Target sectors: government, technology, financial, professional services, consumer, telecommunications
Target regions: Russia, North America, Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583.006, T1608.005, T1587, T1566.002, T1204.001, T1528, T1111, T1621, T1656