Kali365 PhaaS Kit: OAuth Device-Code Phishing Enables MFA-Satisfied Token Theft
ID: 307899fb-6c73-5e01-b88a-8d0077634553
STIX ID: report--307899fb-6c73-5e01-b88a-8d0077634553
Feed Name: Ransomware ISAC Blog
Date Published: 2026-07-03
Date Updated: 2026-08-21
Author: [email protected] (Ransom-ISAC Research Team)
Kali365 (K365) is a commercially sold Phishing‑as‑a‑Service platform (marketed via Telegram) that weaponizes OAuth device‑code flows to capture long‑lived Microsoft 365 refresh tokens; the report presents direct reverse engineering of an operator Electron client, purchased access to a production web panel, a separate fake/testing demo panel (excluded from victim counts), detailed token‑abuse techniques (hidden BrowserWindow seeding → MSAL intercept + bearer injection → SSO cookie export), priority IOCs (domains, wallets, IPs, file hashes), payment/monetization analysis, and actionable detection guidance for Entra ID, network, and endpoint hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
