Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign (TL-2026-0984) is a critical-severity phishing campaign, first published 2026-06-28. It has no confirmed attribution, maps to 26 MITRE ATT&CK techniques (T1020, T1021, T1027.006), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-0984
- Threat ID
- TL-2026-0984
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-06-28
- Last reviewed
- 2026-06-28
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- health, manufacturing, financial-services, insurance, government administration, education, professional-services, energy, construction, telecoms, retail, hospitality
- Target regions
- united states of america, australia, india, canada, Europe, EMEA
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
Malware and tooling: kali365-phaas-platform
Kali365 is a mature, multi-edition phishing-as-a-service (PhaaS) platform that exploits Microsoft's OAuth 2.0 device code authentication flow to steal persistent refresh tokens from Microsoft 365 accounts. The kit bypasses multi-factor authentication and survives password changes, enabling persistent compromise and post-exploitation business email compromise (BEC) attacks. Peak campaign activity on May 20, 2026 saw 80+ successful authentications; the FBI issued PSA I-052126-PSA on May 21 warning of hundreds of organizational compromises.
How Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign works
Kali365, also known as Octopi365 and Freedom365, emerged in April 2026 as a sophisticated phishing-as-a-service platform targeting Microsoft 365 environments globally. The kit exploits a fundamental weakness in Microsoft's device code authentication flow—an OAuth 2.0 mechanism originally intended for IoT and smart TV authentication. Threat actors dynamically generate legitimate device codes from Microsoft's OAuth service and redirect phishing victims to the genuine Microsoft login page (microsoft.com/devicelogin), where victims enter the intercepted code. Upon successful authentication, the attacker receives OAuth access and refresh tokens that grant persistent access to Exchange Online, Teams, OneDrive, and SharePoint—surviving both multi-factor authentication and subsequent password changes.
The platform comprises three distinct editions (E1, E2, E3) with escalating post-compromise capabilities. Edition 1 provides basic token capture and mailbox proxy access via a React-based single-page application with 33+ built-in lure templates impersonating Adobe Acrobat Sign, DocuSign, SharePoint, and OneDrive. Edition 2 layers sophisticated post-compromise automation: an AI-powered Business Email Compromise (BEC) module that analyzes captured mailbox threads to identify high-value targets (wire transfers, invoices, payroll), generates fraudulent replies, and tiers opportunities by fraud scoring. Edition 3 enables self-service cryptocurrency payments and reseller affiliate capabilities via Telegram distribution channels. All editions integrate OxaPay cryptocurrency payment processing and Cloudflare Turnstile bot protection, with infrastructure spanning 240+ compromised IP addresses in the AS132203 (Tencent Cloud) CIDR range. The campaign reached peak activity on May 20, 2026, with 80+ successful authentication events captured in a single day, prompting an FBI critical Public Service Alert on May 21, 2026. Infrastructure evolution includes domain rotation (kali365.xyz → octopi365.com → blackoctopusking.live ~May 7, 2026) and operator expansion into related campaigns targeting MAX Messenger (110M+ registered users) and other cloud platforms. Post-compromise attack chains include mailbox rule creation to suppress security notifications, lateral phishing from compromised accounts to organizational contacts, credential harvesting via forwarding rules, and coordinated BEC operations facilitated by the E2 module's AI-powered targeting.
MITRE ATT&CK techniques used in TL-2026-0984
exfiltration
Lateral Movement
Defense Evasion
T1027.006 HTML Smuggling; T1078.004 Cloud Accounts
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Discovery
T1087.004 Cloud Account; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery
Persistence
T1098.001 Additional Cloud Credentials; T1098.003 Additional Cloud Roles; T1136.003 Cloud Account
Credential Access
T1110.004 Credential Stuffing; T1111 Multi-Factor Authentication Interception; T1187 Forced Authentication
Collection
T1114.001 Local Email Collection; T1114.002 Remote Email Collection
Execution
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
lateral-movement
T1550.001 Application Access Token
defense-impairment
T1556 Modify Authentication Process; T1578 Modify Cloud Compute Infrastructure
Initial Access
reconnaissance
T1589.003 Employee Names; T1598.002 Spearphishing Attachment
Reconnaissance
Impact
Timeline of Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
- Kali365 first observed in the wild; operators begin distribution via Telegram channels and cryptocurrency-gated access
- Campaign phishing infrastructure begins active hosting; panel.securehubcloud.com and related C2 nodes operational in AS132203 (Tencent Cloud)
- Operators retire kali365.xyz and octopi365.com domains (~18:00 UTC); infrastructure migration to blackoctopusking.live and related domains begins
- Huntress SOC detects unusual device code authentication events originating from Tencent Cloud (AS132203) targeting customer organizations
- Campaign reaches peak operational tempo: 80+ successful OAuth token capture events documented in single 24-hour period across multiple organizations
- FBI issues critical Public Service Alert I-052126-PSA warning U.S. organizations of Kali365 phishing-as-a-service campaign; hundreds of compromises already documented
- Campaign phishing activity subsides as operators transition to infrastructure maintenance; focus shifts to post-compromise automation and BEC operations
- MAX Messenger phishing variant identified; operators expand Kali365 infrastructure into AWS, Okta, and Xerox MAX Messenger targeting ecosystem
- Huntress Labs publishes comprehensive threat report documenting Kali365 architecture, capabilities, IoCs, and post-compromise TTPs; Arctic Wolf releases related MAX Messenger campaign analysis
- Campaign remains ACTIVE; operators continue distributing Kali365 editions via Telegram, Cloudflare Workers, and Railway.com; E2/E3 editions with BEC automation observed in operations
Threats related to Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access
Detection coverage for TL-2026-0984
As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0984 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.