From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
ID: 28128eba-1b7d-5bad-9880-e411e33ece5b
STIX ID: report--28128eba-1b7d-5bad-9880-e411e33ece5b
Feed Name: Arctic Wolf Blog
Threat Score
**Executive summary:** Arctic Wolf Labs documents active Kali365 phishing-as-a-service operations that abuse Microsoft’s OAuth 2.0 device authorization flow to capture persistent M365 tokens and run a multi-brand phishing infrastructure (126 hosts) including a targeted MAX Messenger account-takeover campaign; the report identifies a live C2 panel (panel.securehubcloud.com), Telegram-based credential exfiltration, content-based hunting fingerprints, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
