Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Kali365

8
Global rank
1 infographic chevron month
Month rank
1
Week rank
0
IOCs

Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.

Phishingkit
Type
Unknown
Origin
1 April, 2026
First seen
10 September, 2026
Last seen

How to analyze Kali365 with ANY.RUN

Type
Unknown
Origin
1 April, 2026
First seen
10 September, 2026
Last seen

IOCs

IP addresses
23.52.181.141
41.185.8.68
192.178.183.113
20.190.160.14
48.209.6.48
48.209.138.168
20.190.159.0
23.216.77.21
184.24.77.80
20.190.159.71
104.21.29.129
23.11.41.157
2.16.241.201
172.217.113.4
135.233.95.144
95.100.102.101
13.107.246.45
142.251.150.119
172.211.123.249
142.251.127.84
Hashes
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
807882f310ebf263f7b85b683add53970251d3cafb3b22ac3fce9923fb15ab35
7ba53fc9c7a8b57f4f9b01c6ba83b50e83d0662e52134d48a60195a910aa3d86
06ab381e06178f2a0062db9b1d069adf065c4ff00232426b8d70fa3ad7703a76
4c897707a45592774ffc4c65b207589efee2f1667798f96b4e37245047466e3e
dd9ce6b3ae599ee1a027bbd1e53c071cda2f136ee144a7a8597f20e53405a29e
b00a8ae348e6e4f12c3410ba71ed3547764432d21f737b51f7100e5ae7ff0bd3
93332c49fab1deb87dac6cb5d313900cb20e6e1ba928af128a1d549a44256f68
10c8ff7aa63c4a53d8737ff0d432ca406eea1f02b9c57122e155491498a71bd0
25aad5d4507e12952cc8acf3063ca5122c3d4dc28527365154e5c9ad5fe7cfea
5ee004095de29a46de16b78f9020dedfdb3cbe41d2b60ce9e01c6699823f6953
cae66ee75c139fd2f338478a56cd51ba8c0bd51daf931bb48ac88fae665566af
9d6f2ab2cd4f044315a9ac5555cfd434a132b7141c7e626d0a7a0ff6fab8ecda
Domains
slscr.update.microsoft.com
u5mt2w6n01.primaildoc.cc
www.microsoft.com
settings-win.data.microsoft.com
ocsp.digicert.com
aadcdn.msftauth.net
accounts.google.com
go.microsoft.com
fe3cr.delivery.mp.microsoft.com
update.googleapis.com
safebrowsingohttpgateway.googleapis.com
google.com
clientservices.googleapis.com
login.microsoft.com
optimizationguide-pa.googleapis.com
activation-v2.sls.microsoft.com
content-autofill.googleapis.com
login.microsoftonline.com
clients2.google.com
crl.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://clients2.google.com/time/1/current?cup2key=8:g_ogxb7jpsemqfpuqyzkhzvvf_wldaotah25onrpsbg&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://login.microsoft.com//////////////////////////////common/oauth2/v2.0/authorize?state=&scope=openid+profile+https%253a%252f%252fgraph.microsoft.com%252fuser.read&prompt=none&client_id=990bf814-a34d-47fc-88e3-b9daa709e62c&uri=https%253a%252f%252fdeveloper.salesforce.com%252fdashboard%252fsession%252fuser%252fverify%252fstep1&%255ca3edq%250c+2e4c%250d%250a%2593bb66f835%2509%258c2979x%25bcint+builder.decode%250a%2509context+%253a%253d+flowemail+%255b+offsetstream+%253a=%2520token%2509data%2520%257c%2520email%257dfor%2520stream%253a%253dpayloadbuilder+;+valuecontext+%257d+trace%250a%2509decode+.+signalvector+%257b%2520offset%257d%250aa78c998ef06b569e%2597%25e9%252a%25cba93627d06a07eba872664f4a92c74eae25f60308d1cad09a16e7beef0b79c03d8bd7528c4a7efc8bdb3fc053evar%252bvector-secret%25250a%252509decode%252b%25253b%252bbuffer%25250a%252509encode%252b-%252bsession%25250a%252509decode%252b%25255d%252bpayload%25250a%252509offset%252b%25252b%252bbuilder%25250a%252509builder%252b%252528%252btoken%25250a%252509encode%252b.%252bkey%25250a%252509context%252b%25257b%252btoken%25250a%25257d%25250aelse%252bdecode%25252cbuilder%25250a%252509stream%252b%25253a%25253d%252bheader%25250a%252509vector%252b%252526%252bvector%25250a%252509payload%252b%25253d%252bbuilder%25250a%252509value%252b%25257c%252bpayload%25250a%252509secret%252b%25253d%252bbuffer%25250a%25257d%25250aswitch%252bpayload%25252csession%25250a%252509payload%252b%252529%252btoken%25250a%252509payload%252b%252526%252bbuilder%25250a%252509data%252b%25257c%252bdecode%25250a%252509secret%252b%25255b%252bstream%25250a%25257d%25250astring%252bbody%252529session%25250a%252509session%252b%252528%252btrace%25250a%252509buffer%252b%25257b%252bsession%25250a%252509vector%252b%25252a%252bvector%25250a%252509context%252b%25253b%252btoken%25250a%252509value%252b%25252a%252bdata%25250a%252509encode%252b%25253b%252bflow%25250a%252509trace%252b%252529%252btrace%25250a%25257d%25250aint%252btoken%25257csignal%25250a%252509header%252b%25255d%252bflow%25250a%252509body%252b.%252bkey%25250a%252509vector%252b%252528%252bsignal%25250a%252509session%252b%25252c%252bdata%25250a%25257d%25250ac2fuzgvlcebmdmnvbs5hzq==
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?state=&scope=openid+profile+https%253a%252f%252fgraph.microsoft.com%252fuser.read&prompt=none&client_id=990bf814-a34d-47fc-88e3-b9daa709e62c&uri=https%253a%252f%252fdeveloper.salesforce.com%252fdashboard%252fsession%252fuser%252fverify%252fstep1&%255ca3edq%250c+2e4c%250d%250a%2593bb66f835%2509%258c2979x%25bcint+builder.decode%250a%2509context+%253a%253d+flowemail+%255b+offsetstream+%253a=%2520token%2509data%2520%257c%2520email%257dfor%2520stream%253a%253dpayloadbuilder+;+valuecontext+%257d+trace%250a%2509decode+.+signalvector+%257b%2520offset%257d%250aa78c998ef06b569e%2597%25e9%252a%25cba93627d06a07eba872664f4a92c74eae25f60308d1cad09a16e7beef0b79c03d8bd7528c4a7efc8bdb3fc053evar%252bvector-secret%25250a%252509decode%252b%25253b%252bbuffer%25250a%252509encode%252b-%252bsession%25250a%252509decode%252b%25255d%252bpayload%25250a%252509offset%252b%25252b%252bbuilder%25250a%252509builder%252b%252528%252btoken%25250a%252509encode%252b.%252bkey%25250a%252509context%252b%25257b%252btoken%25250a%25257d%25250aelse%252bdecode%25252cbuilder%25250a%252509stream%252b%25253a%25253d%252bheader%25250a%252509vector%252b%252526%252bvector%25250a%252509payload%252b%25253d%252bbuilder%25250a%252509value%252b%25257c%252bpayload%25250a%252509secret%252b%25253d%252bbuffer%25250a%25257d%25250aswitch%252bpayload%25252csession%25250a%252509payload%252b%252529%252btoken%25250a%252509payload%252b%252526%252bbuilder%25250a%252509data%252b%25257c%252bdecode%25250a%252509secret%252b%25255b%252bstream%25250a%25257d%25250astring%252bbody%252529session%25250a%252509session%252b%252528%252btrace%25250a%252509buffer%252b%25257b%252bsession%25250a%252509vector%252b%25252a%252bvector%25250a%252509context%252b%25253b%252btoken%25250a%252509value%252b%25252a%252bdata%25250a%252509encode%252b%25253b%252bflow%25250a%252509trace%252b%252529%252btrace%25250a%25257d%25250aint%252btoken%25257csignal%25250a%252509header%252b%25255d%252bflow%25250a%252509body%252b.%252bkey%25250a%252509vector%252b%252528%252bsignal%25250a%252509session%252b%25252c%252bdata%25250a%25257d%25250ac2fuzgvlcebmdmnvbs5hzq==
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?state=&scope=openid+profile+https%253a%252f%252fgraph.microsoft.com%252fuser.read&prompt=none&client_id=990bf814-a34d-47fc-88e3-b9daa709e62c&uri=https%253a%252f%252fdeveloper.salesforce.com%252fdashboard%252fsession%252fuser%252fverify%252fstep1&%255ca3edq%250c+2e4c%250d%250a%2593bb66f835%2509%258c2979x%25bcint+builder.decode%250a%2509context+%253a%253d+flowemail+%255b+offsetstream+%253a=%2520token%2509data%2520%257c%2520email%257dfor%2520stream%253a%253dpayloadbuilder+;+valuecontext+%257d+trace%250a%2509decode+.+signalvector+%257b%2520offset%257d%250aa78c998ef06b569e%2597%25e9%252a%25cba93627d06a07eba872664f4a92c74eae25f60308d1cad09a16e7beef0b79c03d8bd7528c4a7efc8bdb3fc053evar%252bvector-secret%25250a%252509decode%252b%25253b%252bbuffer%25250a%252509encode%252b-%252bsession%25250a%252509decode%252b%25255d%252bpayload%25250a%252509offset%252b%25252b%252bbuilder%25250a%252509builder%252b%252528%252btoken%25250a%252509encode%252b.%252bkey%25250a%252509context%252b%25257b%252btoken%25250a%25257d%25250aelse%252bdecode%25252cbuilder%25250a%252509stream%252b%25253a%25253d%252bheader%25250a%252509vector%252b%252526%252bvector%25250a%252509payload%252b%25253d%252bbuilder%25250a%252509value%252b%25257c%252bpayload%25250a%252509secret%252b%25253d%252bbuffer%25250a%25257d%25250aswitch%252bpayload%25252csession%25250a%252509payload%252b%252529%252btoken%25250a%252509payload%252b%252526%252bbuilder%25250a%252509data%252b%25257c%252bdecode%25250a%252509secret%252b%25255b%252bstream%25250a%25257d%25250astring%252bbody%252529session%25250a%252509session%252b%252528%252btrace%25250a%252509buffer%252b%25257b%252bsession%25250a%252509vector%252b%25252a%252bvector%25250a%252509context%252b%25253b%252btoken%25250a%252509value%252b%25252a%252bdata%25250a%252509encode%252b%25253b%252bflow%25250a%252509trace%252b%252529%252btrace%25250a%25257d%25250aint%252btoken%25257csignal%25250a%252509header%252b%25255d%252bflow%25250a%252509body%252b.%252bkey%25250a%252509vector%252b%252528%252bsignal%25250a%252509session%252b%25252c%252bdata%25250a%25257d%25250ac2fuzgvlcebmdmnvbs5hzq==&sso_reload=true
https://aadcdn.msauth.net/shared/1.0/content/js/bssointerrupt_core_qyzshzeymyfrceh9fs-4bq2.js
https://login.microsoftonline.com/favicon.ico
https://identity.nel.measure.office.net/api/report?catid=gw+estsfd+dub2
https://aadcdn.msftauth.net/shared/1.0/content/js/fetchsessions_core_89q4ntpu5d04aggkhtgcrq2.js
https://login.live.com/me.htm?v=3
https://ballcuie.footballstats.be/lss?error=interaction_required&error_description=session+information+is+not+sufficient+for+single-sign-on.
https://ballcuie.footballstats.be/lss/?error=interaction_required&error_description=session+information+is+not+sufficient+for+single-sign-on.
https://u5mt2w6n01.primaildoc.cc/l/8zvgorue2hw
https://u5mt2w6n01.primaildoc.cc/favicon.ico
https://content-autofill.googleapis.com/v1/pages/chvdahjvbwuvmtmzljaunjk0my4xmjcsgqn3kxwig_azqbifdfurvj0hbhdpwiryv9m=?alt=proto
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 482
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 3118
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 5883
comments 0

No Password, No Problem: How Kali365 Is Breaking Into Microsoft 365 Environments at Scale

Key Takeaways

  • Kali365 is an FBI-flagged PhaaS platform that emerged in April 2026 and enables even low-skilled attackers to compromise Microsoft 365 accounts using AI-powered phishing tools and automated OAuth token capture.

  • MFA does not stop Kali365. Every documented victim organization was using multi-factor authentication. The platform's device code phishing method exploits a legitimate Microsoft authentication flow, meaning MFA is never triggered.

  • Stolen OAuth tokens provide persistent, password-free access to Outlook, Teams, and OneDrive. The refresh token keeps attackers inside indefinitely, and from Microsoft's perspective the session looks entirely legitimate.

  • Post-compromise behavior is automated and stealthy. Kali365 attackers create inbox rules to suppress security alerts and can register new devices in the victim's environment — extending their foothold beyond the initial token.

  • Any organization using Microsoft 365 is in scope. Documented victims span healthcare, finance, insurance, manufacturing, government, and education across North America, Europe, and APAC — the common factor is Microsoft 365 adoption, not sector-specific vulnerability.

  • The most direct technical mitigation is disabling device code flow. Organizations should create Conditional Access policies in Microsoft Entra to block or restrict device code authentication, audit existing usage, and block authentication transfer policies.

  • Proactive threat intelligence is essential for early defense. ANY.RUN's Threat Intelligence Lookup and Threat Intelligence Feeds give security teams immediate access to Kali365 IOCs, known malicious infrastructure, and real-time campaign data — enabling teams to block phishing infrastructure, enrich authentication logs, and hunt for active compromises before attackers establish persistence.

    threatName:"kali365".

Explore Kali365 campaigns with ANY.RUN Explore Kali365 campaigns with ANY.RUN

What is Kali365?

Kali365 is a subscription-based cybercrime service distributed primarily through Telegram, offering aspiring attackers a turnkey toolkit for compromising Microsoft 365 environments at scale.

The platform's defining characteristic is its exploitation of Microsoft's OAuth 2.0 Device Authorization Grant flow, commonly known as "device code phishing." This legitimate authentication mechanism was originally created to let input-limited devices (smart TVs, conference room displays, printers, IoT hardware) sign into Microsoft 365 by generating a short code on a secondary device and entering it at a genuine Microsoft authorization page (microsoft.com/devicelogin).

Kali365 hijacks this flow: the attacker generates the code, the victim enters it at a real Microsoft URL — believing they are completing a routine verification — and Microsoft then hands the attacker an OAuth access token and a refresh token.

The critical consequence: no password is ever captured, and no additional MFA challenge is triggered. The victim may believe they acted safely, having visited a genuine Microsoft domain with a valid SSL certificate. The attacker, meanwhile, has obtained a persistent digital key granting unfettered access to the victim's Microsoft 365 environment.

Beyond device code phishing Kali365 also offers a second attack mode called "Cookie Link" — an adversary-in-the-middle (AitM) capability. Here, victims are sent a phishing email containing a cookie-based lure that transparently proxies their browser through attacker-controlled infrastructure, capturing authenticated session cookies, session tokens, and MFA solutions in real time.

ANY.RUN Interactive Sandbox lets analysts see the full phishing flow, validate detection logic, and collect IOCs.

View a Kali365 sample analysis

Kali365 detonated in Interactive Sandbox Kali365 detonated in Interactive Sandbox

Deobfuscated Kali365 JavaScript revealed that after a verification gate, the lure deploys a phishing page, launches a legitimate Microsoft device authentication flow, and then polls /api/status/ for session states such as captured, expired, and declined.

The code also contains lure-template generators for OneDrive, SharePoint, Teams, Outlook, and Voicemail, and a separate Google device-code authentication flow.

Kali365 kill chain elements Kali365 kill chain elements

How Kali365 Threatens Businesses and Organizations

For organizations, Kali365 is much more than another phishing kit. Once attackers gain access to a Microsoft 365 environment, they can:

1. Conduct Business Email Compromise (BEC)

Attackers can monitor executive communications, intercept invoices, alter payment instructions, and launch fraud campaigns from trusted accounts.

2. Steal Sensitive Data

Access to Outlook, Teams, OneDrive, and SharePoint may expose:

  • Financial records,
  • Strategic plans,
  • Customer information,
  • Legal documents,
  • Intellectual property,
  • Enable Lateral Movement.

Compromised cloud accounts often serve as a foothold for further attacks against corporate infrastructure.

3. Launch Additional Social Engineering Campaigns

Threat actors can use trusted internal accounts to distribute malicious links and phishing emails across the organization.

4. Facilitate Ransomware Operations

Access to business communications and cloud resources can help attackers identify high-value assets and prepare ransomware deployment. Because Kali365 grants persistent access through stolen OAuth tokens, attackers may retain access even after passwords are changed unless the tokens themselves are revoked

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most Vulnerable?

Security firms Arctic Wolf, Proofpoint, and Huntress documented Kali365 campaigns targeting organizations across North America (United States, Canada), Europe, and the broader EMEA region, as well as Australia and New Zealand, within weeks of the platform's April 2026 launch. The targeted sectors span a wide range:

Healthcare is particularly exposed. Microsoft 365 is deeply embedded in healthcare workflows for document sharing, internal communications, billing, and patient administration. A compromised account can mean unauthorized access to protected health information, internal clinical communications, and billing systems — with potentially severe regulatory consequences under frameworks such as HIPAA.

Financial services and insurance face direct risks of fraud, fund transfer manipulation, and sensitive client data exposure. BEC attacks originating from legitimately authenticated internal accounts are especially difficult to detect and defend against.

Government agencies are high-value targets for espionage, data theft, and disruption. The fact that Kali365 bypasses MFA — a control many government mandates consider sufficient — makes it a particularly pressing concern for public sector security.

Manufacturing relies heavily on Microsoft 365 for supply chain communication and operational coordination. Compromised accounts can enable industrial espionage, disrupt production, or facilitate invoice fraud.

Any organization running Microsoft 365 is actually within scope. The attack does not exploit a Microsoft vulnerability: it exploits the device code authentication flow that is enabled by default. Unless organizations have explicitly restricted or blocked device code flow via Conditional Access policies, every Microsoft 365 user is a potential target.

How Kali365 Gets Into Systems and Spreads

The Kali365 infection chain begins with a targeted phishing email and follows a carefully constructed sequence:

Step 1 — The Lure. The attacker sends a phishing email impersonating a trusted cloud productivity or document-sharing service. Commonly impersonated brands include Adobe Acrobat Sign, DocuSign, SharePoint, and Microsoft itself. The email typically communicates urgency — a document requiring signature, a file ready for review, or an account requiring verification. It contains a device code and instructions to visit a legitimate Microsoft URL (microsoft.com/devicelogin).

Step 2 — Authorization. The recipient, seeing a familiar and legitimate Microsoft URL, navigates to the real Microsoft page and enters the code. Password managers recognize the domain correctly. The SSL certificate is valid. There is no typo in the URL. The victim believes they have acted safely.

Step 3 — Token Theft. Unknown to the victim, the attacker generated the device code. By entering it on the Microsoft page, the victim authorizes the attacker's application to access their account. Microsoft hands the attacker an OAuth access token and a refresh token.

Step 4 — Persistence and Lateral Movement. The attacker now has persistent access to Outlook, Teams, OneDrive, and any other Microsoft 365 resources the victim's account can reach. Without a password, without MFA. Malicious inbox rules are created to suppress security notifications. New devices may be registered in the victim's environment. The attacker can move laterally, impersonate the victim, access connected systems, and escalate privileges.

The second attack mode, Cookie Link, follows a slightly different path: the phishing lure directs victims to a page that transparently proxies their entire authenticated browser session through attacker-controlled infrastructure. Session cookies and tokens are captured server-side as the victim logs in and completes MFA normally — with the AitM infrastructure intercepting everything in transit.

The platform spreads through Telegram channels targeting cybercriminal communities, where it is promoted by resellers and discussed in forums alongside pricing, tutorials, and affiliate onboarding materials.

How Does Kali365 Malware Function?

At the technical level, Kali365 is built around two core capabilities that can be deployed independently or in combination.

Device Code Phishing Mode exploits the OAuth 2.0 Device Authorization Grant flow as follows: the attacker initiates an OAuth device authorization request to Microsoft's servers, which returns a device code and a user verification URL. The attacker embeds this code in a phishing email and distributes it to targets.

When the victim enters the code at microsoft.com/devicelogin, they complete the device authorization grant — and Microsoft's authorization server returns an OAuth access token and refresh token to the attacker's polling application. The access token grants immediate API-level access to Microsoft 365 services. The refresh token can be used to request new access tokens indefinitely, making the session persistent even if the original access token expires.

Cookie Link (AitM) Mode operates by deploying a reverse proxy server between the victim and Microsoft's legitimate authentication servers. The victim's browser communicates with what appears to be a legitimate service, but all traffic — including the session cookies generated after successful MFA — passes through the attacker's infrastructure. The attacker captures the authenticated session cookies and tokens directly, bypassing MFA entirely because the victim completed MFA legitimately; the attacker simply intercepted the result.

Post-Compromise Automation distinguishes Kali365 from simpler phishing kits. Upon receiving captured tokens, the platform can automatically create malicious inbox rules within compromised mailboxes. These rules silently reroute and suppress emails containing specific keywords associated with security warnings or phishing alerts. Attackers can then use the platform's dashboard to monitor and manage compromised accounts, export captured tokens, and share access with other affiliates, effectively commoditizing post-compromise access.

The platform's AI-generated phishing lures are produced in real time, customized per campaign and target, and localized into 15 languages, dramatically increasing the realism and geographic scale of campaigns compared to manually crafted phishing emails.

How Businesses Can Use ANY.RUN’s Threat Intelligence Feeds and TI Lookup Against Kali365

Kali365's architecture presents detection challenges that traditional security tools struggle to address — but threat intelligence solutions specifically designed for proactive defense can meaningfully reduce the risk.

Using Threat Intelligence Feeds for Early Detection and Blocking

ANY.RUN's Threat Intelligence Feeds provide continuously updated indicators associated with phishing campaigns and malicious infrastructure.

Security teams can:

  • Automatically enrich SIEMs and security controls;
  • Block known malicious domains and URLs;
  • Detect emerging phishing infrastructure;
  • Improve email security effectiveness;
  • Reduce exposure to newly discovered campaigns.

TI Feeds benefits and integration TI Feeds benefits and integration

ANY.RUN Threat Intelligence Lookup enables security teams to query a continuously updated database of threat indicators, malware behaviors, file hashes, IP addresses, and domains associated with known threat actors and campaigns. For Kali365 specifically, TI Lookup allows organizations to:

  • Search for Indicators of Compromise (IOCs) linked to Kali365 infrastructure, including known malicious domains (such as kali365[.]xyz and associated sibling servers) and IP addresses used in campaigns documented by Arctic Wolf, Huntress, and the FBI.

  • Query for OAuth token theft behaviors, device code phishing patterns, and AitM proxy infrastructure signatures to understand whether any matching activity has touched the organization's environment.

  • Investigate suspicious authentication events by pivoting on observed IPs, user agents, or domain names — rapidly determining whether anomalous sign-in activity corresponds to a documented Kali365 campaign.

domainName:"hesmucbsb.prodcamp.com".

Domain exposed as part of Kali365 infrastructure Domain exposed as part of Kali365 infrastructure

Besides, organizations should take the following measures:

  • Block or restrict device code flow via Microsoft Entra Conditional Access policies. This is the single most direct technical mitigation against Kali365's primary attack mode. Organizations should audit existing device code usage to identify legitimate dependencies before enforcement.

  • Block authentication transfer policies to prevent session transfers between devices.

  • Monitor for suspicious OAuth application registrations and anomalous sign-in patterns, particularly logins from new IP addresses or geographies, new device registrations, and access from devices not enrolled in device management.

  • Deploy advanced identity security tooling capable of detecting anomalous token usage patterns — not just credential compromise or MFA bypass attempts.

  • Audit and alert on malicious inbox rules that route, delete, or suppress security-related emails, as these are a consistent post-compromise behavioral indicator in Kali365 attacks.

  • Conduct phishing awareness training specifically addressing device code phishing scenarios. Users need to understand that entering a short code on a real Microsoft page can still result in account compromise if the code originated from an attacker.

  • Implement SIEM correlation rules that flag device code authentication events originating from unfamiliar IP addresses or combined with other risk signals.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Kali365 demonstrates how modern phishing campaigns are evolving beyond password theft. By abusing legitimate Microsoft authentication workflows and targeting OAuth tokens instead of credentials, the platform enables attackers to bypass MFA and gain persistent access to business environments.

As Phishing-as-a-Service ecosystems continue to mature, organizations can no longer rely solely on passwords and MFA for protection. Effective defense requires visibility into phishing infrastructure, continuous monitoring of cloud identities, proactive threat intelligence, and rapid detection of suspicious authentication activity.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
Gunra screenshot
Gunra
gunra
Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.
Read More
Emmenhtal screenshot
Emmenhtal
emmenhtal
First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More