← Back to Pulse Feed
PULSE DETAIL
In early April 2026, a large-scale device code phishing campaign targeted organizations across multiple sectors and regions, exploiting OAuth 2.0 Device Authorization Grant. Threat actors leveraged the Kali365 phishing-as-a-service platform, originating primarily from IP address 216.203.20[.]95. The campaign used high-fidelity lures directing victims to Microsoft's legitimate device login flow, where users unknowingly authorized threat actor-controlled sessions. Captured OAuth tokens enabled immediate mailbox access and post-compromise activities. In some cases, attackers established malicious inbox rules to suppress security notifications, extending dwell time. The Kali365 platform operates as a multi-tenant PhaaS ecosystem supporting both device code abuse and adversary-in-the-middle session capture, featuring rapid lure generation across multiple languages and file types, Cloudflare Worker-hosted pages, and token sharing capabilities between affiliates.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Kali365
Indicators of Compromise (3 / 9 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 09bb7e568e573497e22bfa3f36d71fe9d104899826608affedb25d988f391c85 | — | 2026-04-25 | |
| FileHash-SHA256 | 2fa6fc2199d3be55e240500d87e4484f39b9315bf336be25434f6716b8d28ec8 | — | 2026-04-25 | |
| FileHash-SHA256 | 883d5d4a73b0ac8cf4f78fe46d8f4e76e21508872836f2b439af2de4a205128e | — | 2026-04-25 |