Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign — Threadlinqs Intelligence
As of 2026-06-28, Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign is a critical-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0984 · Severity: CRITICAL · Status: ACTIVE · Category: PHISHING
Kali365 is a mature, multi-edition phishing-as-a-service (PhaaS) platform that exploits Microsoft's OAuth 2.0 device code authentication flow to steal persistent refresh tokens from Microsoft 365
Kali365, also known as Octopi365 and Freedom365, emerged in April 2026 as a sophisticated phishing-as-a-service platform targeting Microsoft 365 environments globally. The kit exploits a fundamental weakness in Microsoft's device code authentication flow—an OAuth 2.0 mechanism originally intended for IoT and smart TV authentication. Threat actors dynamically generate legitimate device codes from Microsoft's OAuth service and redirect phishing victims to the genuine Microsoft login page (microsoft.com/devicelogin), where victims enter the intercepted code. Upon successful authentication, the attacker receives OAuth access and refresh tokens that grant persistent access to Exchange Online, Teams, OneDrive, and SharePoint—surviving both multi-factor authentication and subsequent password changes.
The platform comprises three distinct editions (E1, E2, E3) with escalating post-compromise capabilities. Edition 1 provides basic token capture and mailbox proxy access via a React-based single-page application with 33+ built-in lure templates impersonating Adobe Acrobat Sign, DocuSign, SharePoint, and OneDrive. Edition 2 layers sophisticated post-compromise automation: an AI-powered Business Email Compromise (BEC) module that analyzes captured mailbox threads to identify high-value targets (wire transfers, invoices, payroll), generates fraudulent replies, and tiers opportunities by fraud scoring. Edition 3 enables self-service cryptocurrency payments and reseller affiliate capabilities via Telegram distribution channels. All editions integrate OxaPay cryptocurrency payment processing and Cloudflare Turnstile bot protection, with infrastructure spanning 240+ compromised IP addresses in the AS132203 (Tencent Cloud) CIDR range. The campaign reached peak activity on May 20, 2026, with 80+ successful authentication events captured in a single day, prompting an FBI critical Public Service Alert on May 21, 2026. Infrastructure evolution includes domain rotation (kali365.xyz → octopi365.com → blackoctopusking.live ~May 7, 2026) and operator expansion into related campaigns targeting MAX Messenger (110M+ registered users) and other cloud platforms. Post-compromise attack chains include mailbox rule creation to suppress security notifications, lateral phishing from compromised accounts to organizational contacts, credential harvesting via forwarding rules, and coordinated BEC operations facilitated by the E2 module's AI-powered targeting.
Target sectors: health, manufacturing, financial-services, insurance, government administration, education, professional-services, energy, construction, telecoms, retail, hospitality
Target regions: united states of america, australia, india, canada, Europe, EMEA
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, CRITICAL, threat intelligence, cybersecurity, T1566.002, T1598.002, T1204.001, T1098.001, T1098.003, T1136.003, T1548, T1556, T1550.001, T1078.004