Kali365
MITRE ATT&CK: S9044 View on attack.mitre.org
Aliases: Kali365
- Profile updated
- 2026-08-15 03:00:05
Context
Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. (Citation: Huntress Kali365 Device Code June 2026) Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) Kali365 PHaaS was first observed in April 2026.(Citation: Artic Wolf Labs Kali365 Device Code April 2026) Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.(Citation: Huntress Kali365 Device Code June 2026)
Reports & references
- arcticwolf.com — Kali365 Expands Into Aws Microsoft Okta Xerox Max Messenger (report)
- arcticwolf.com — Token Bingo Dont Let Your Code Be The Winner (report)
- MITRE ATT&CK — S9044 (report)
- spycloud.com — Kali365 Anatomy Of A Microsoft365 Phishing As A Service Kit (report)
- huntress.com — Kali365 Device Code Phishing Kit (report)
- ic3.gov — Psa260521 (report)