logo

Kali365 PhaaS Kit: OAuth Device-Code Phishing Enables MFA-Satisfied Token Theft

ID: 4114e968-1016-555e-bff9-631542353ce3

STIX ID: report--4114e968-1016-555e-bff9-631542353ce3

Feed Name: Ransomware ISAC Blog

Threat Score
78/100

Date Published: 2026-07-03

Date Updated: 2026-07-29

Author: [email protected] (Ransom-ISAC Research Team)

...
...

Kali365 (K365) is a subscription Phishing‑as‑a‑Service sold via Telegram that uses OAuth device‑code phishing to capture long‑lived Microsoft 365 refresh tokens. The report separates three evidence streams—reverse‑engineered operator client (kali365.exe), purchased access to a legitimate web panel, and a fake/testing panel—and confirms the operator client unpacks to an Electron/TypeScript app that polls a backend (v2.duemineral.uk) for stolen tokens and offers one‑click access to Outlook/Admin Center via token injection and SSO cookie export. The service is monetized via subscriptions and bulk “lines” of stolen tokens, includes n8n-based lure orchestration, and provides numerous IOCs (domains, IPs, wallet addresses, file hashes) together with Entra ID/Azure AD and endpoint detection guidance; victim counts remain unconfirmed where sourced from the fake panel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.