← Back to Pulse Feed
PULSE DETAIL
Kali365 (aka Kali365 Live) is a multi-tenant Microsoft 365 phishing-as-a-service platform first seen April 2026, promoted via Telegram, ~$250/30 days or $2,000/year via the non-KYC processor Trocador. It abuses the OAuth 2.0 device authorization grant ("device code flow") to capture access and refresh tokens, bypassing MFA without handling a password, and offers a separate AitM "Cookie Link" mode for session-cookie theft. Features: AI-generated lures, Cloudflare Worker-hosted pages impersonating Adobe Acrobat Sign, DocuSign, SharePoint, OneDrive and Teams, token sharing between affiliates, and an Electron desktop client. Post-compromise activity includes malicious inbox rules to suppress alerts and rogue Entra ID device registration. Arctic Wolf documented hundreds of attacks across North America and EMEA; the FBI issued advisory PSA260521 on 21 May 2026. Kali365 shares infrastructure and lineage with the EvilTokens/CLURE device-code kits.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4 / 94 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 68056a9a5c70eae8f2054fe00676788503cf59a0 | SHA1 of 09bb7e568e573497e22bfa3f36d71fe9d104899826608affedb25d988f391c85 | 2026-05-28 | |
| FileHash-SHA1 | e33c178c1526361029bbfd6b24664db4da9f7f26 | SHA1 of 2fa6fc2199d3be55e240500d87e4484f39b9315bf336be25434f6716b8d28ec8 | 2026-05-28 | |
| FileHash-SHA1 | 68056a9a5c70eae8f2054fe00676788503cf59a0 | SHA1 of 09bb7e568e573497e22bfa3f36d71fe9d104899826608affedb25d988f391c85 | 2026-05-28 | |
| FileHash-SHA1 | e33c178c1526361029bbfd6b24664db4da9f7f26 | SHA1 of 2fa6fc2199d3be55e240500d87e4484f39b9315bf336be25434f6716b8d28ec8 | 2026-05-28 |
References (3)
↗ https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
↗ https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-kali365-phishing-kit-breaks-microsoft-365-accounts-no-password-required
↗ https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/