Kali365

MITRE ATT&CK: S9044 View on attack.mitre.org

Aliases: Kali365

Profile updated
2026-08-15 03:00:05

Context

Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. (Citation: Huntress Kali365 Device Code June 2026) Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) Kali365 PHaaS was first observed in April 2026.(Citation: Artic Wolf Labs Kali365 Device Code April 2026) Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.(Citation: Huntress Kali365 Device Code June 2026)

Reports & references

  • arcticwolf.com — Kali365 Expands Into Aws Microsoft Okta Xerox Max Messenger (report)
  • arcticwolf.com — Token Bingo Dont Let Your Code Be The Winner (report)
  • MITRE ATT&CK — S9044 (report)
  • spycloud.com — Kali365 Anatomy Of A Microsoft365 Phishing As A Service Kit (report)
  • huntress.com — Kali365 Device Code Phishing Kit (report)
  • ic3.gov — Psa260521 (report)

External references