logo

Token Bingo: Don’t Let Your Code be the Winner

ID: 598c3bd3-0391-51c0-a1db-b9ceb86117a0

STIX ID: report--598c3bd3-0391-51c0-a1db-b9ceb86117a0

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-06-11

...
...

Arctic Wolf observed a widespread device-code phishing campaign in early April 2026 leveraging a multi-tenant PhaaS called Kali365 Live to generate realistic lures and capture Microsoft OAuth tokens or proxied session cookies (AitM). Affiliates use Cloudflare Workers to host phishing pages, share captured tokens, and access compromised Microsoft 365 mailboxes (including creating inbox rules and registering devices); key IOCs include three TCP/8443 hosts (216.203.20.95, 162.243.166.119, 199.91.220.111), a TLS certificate hash, phishing page hashes, and the kali365-live/1.0.0 user-agent, and Arctic Wolf provides recommendations to block device code flow where not required and to improve user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.