logo

From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services

ID: 28128eba-1b7d-5bad-9880-e411e33ece5b

STIX ID: report--28128eba-1b7d-5bad-9880-e411e33ece5b

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2026-06-02

Date Updated: 2026-06-11

...
...

**Executive summary:** Arctic Wolf Labs documents active Kali365 phishing-as-a-service operations that abuse Microsoft’s OAuth 2.0 device authorization flow to capture persistent M365 tokens and run a multi-brand phishing infrastructure (126 hosts) including a targeted MAX Messenger account-takeover campaign; the report identifies a live C2 panel (panel.securehubcloud.com), Telegram-based credential exfiltration, content-based hunting fingerprints, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.