PULSE NAME
Kali365 Device Code Phishing-as-a-Service (M365)
WHITE KorporateKevin 2026-05-28 Modified: 2026-05-28
94
IOCs
HIGH VOLUME
Kali365 (aka Kali365 Live) is a multi-tenant Microsoft 365 phishing-as-a-service platform first seen April 2026, promoted via Telegram, ~$250/30 days or $2,000/year via the non-KYC processor Trocador. It abuses the OAuth 2.0 device authorization grant ("device code flow") to capture access and refresh tokens, bypassing MFA without handling a password, and offers a separate AitM "Cookie Link" mode for session-cookie theft. Features: AI-generated lures, Cloudflare Worker-hosted pages impersonating Adobe Acrobat Sign, DocuSign, SharePoint, OneDrive and Teams, token sharing between affiliates, and an Electron desktop client. Post-compromise activity includes malicious inbox rules to suppress alerts and rogue Entra ID device registration. Arctic Wolf documented hundreds of attacks across North America and EMEA; the FBI issued advisory PSA260521 on 21 May 2026. Kali365 shares infrastructure and lineage with the EvilTokens/CLURE device-code kits.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Kali365 EvilToken CLURE
Indicators of Compromise (4 / 94 total)
All domain FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 68056a9a5c70eae8f2054fe00676788503cf59a0 SHA1 of 09bb7e568e573497e22bfa3f36d71fe9d104899826608affedb25d988f391c85 2026-05-28
FileHash-SHA1 e33c178c1526361029bbfd6b24664db4da9f7f26 SHA1 of 2fa6fc2199d3be55e240500d87e4484f39b9315bf336be25434f6716b8d28ec8 2026-05-28
FileHash-SHA1 68056a9a5c70eae8f2054fe00676788503cf59a0 SHA1 of 09bb7e568e573497e22bfa3f36d71fe9d104899826608affedb25d988f391c85 2026-05-28
FileHash-SHA1 e33c178c1526361029bbfd6b24664db4da9f7f26 SHA1 of 2fa6fc2199d3be55e240500d87e4484f39b9315bf336be25434f6716b8d28ec8 2026-05-28