PULSE NAME
Token Bingo: Don't Let Your Code be the Winner
WHITE AlienVault 2026-04-25 Modified: 2026-04-27
9
IOCs
LOW VOLUME
In early April 2026, a large-scale device code phishing campaign targeted organizations across multiple sectors and regions, exploiting OAuth 2.0 Device Authorization Grant. Threat actors leveraged the Kali365 phishing-as-a-service platform, originating primarily from IP address 216.203.20[.]95. The campaign used high-fidelity lures directing victims to Microsoft's legitimate device login flow, where users unknowingly authorized threat actor-controlled sessions. Captured OAuth tokens enabled immediate mailbox access and post-compromise activities. In some cases, attackers established malicious inbox rules to suppress security notifications, extending dwell time. The Kali365 platform operates as a multi-tenant PhaaS ecosystem supporting both device code abuse and adversary-in-the-middle session capture, featuring rapid lure generation across multiple languages and file types, Cloudflare Worker-hosted pages, and token sharing capabilities between affiliates.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Kali365
Indicators of Compromise (3 / 9 total)
All FileHash-SHA256 IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 09bb7e568e573497e22bfa3f36d71fe9d104899826608affedb25d988f391c85 2026-04-25
FileHash-SHA256 2fa6fc2199d3be55e240500d87e4484f39b9315bf336be25434f6716b8d28ec8 2026-04-25
FileHash-SHA256 883d5d4a73b0ac8cf4f78fe46d8f4e76e21508872836f2b439af2de4a205128e 2026-04-25