IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AITool / Campaign Snapshot

Kali365

A Deeper Look at the PhaaS Platform

Campaign snapshotOAuth tokensPhishing platform
Published
21-Jun-2026
Brief Version
v1.0
Updated
0x via AI Monitoring Agents
Next AI Monitor
Pending AI monitoring agent assignment
Brief ID
PANDA-CTAS-KALI365-2026-001
Template
Campaign, Tool or Actor Snapshot Template v1.0

Research Framing

Kali365 Campaign / Tool Snapshot

1-Topic

This snapshot profiles Kali365 as a Microsoft 365-focused phishing-as-a-service ecosystem that packages OAuth device-code abuse, token capture, lures, templates, dashboards, and campaign tooling for criminal operators. 1, 4, 15, 16, 17

The core defensive question is whether a user was induced to enter an attacker-supplied code into Microsoft's legitimate verification flow, producing token/session or OAuth artifacts that can survive ordinary password-reset playbooks. 1, 5, 6, 18

Treat the page as a tool/campaign profile, not as a victim list or actor attribution claim. Public sources used here do not identify a confirmed operator identity, named victim organizations, complete panel inventory, acquisition path, or stable Kali365 IOC set.

2-Persona / Audience Lens

3-BLUF

  • Kali365 is best treated as a PhaaS platform/tool ecosystem, not a single named threat actor group or one campaign. 1, 15, 16, 17
  • Its significance is the packaging of Microsoft 365 OAuth device-code abuse into a subscription-style service with lures, templates, dashboards, and automation. 1, 4, 15, 16
  • The attacker abuses trust in Microsoft's legitimate verification flow by supplying the code and controlling the authorization context. 1, 5, 18
  • Defense requires token/session revocation, OAuth consent review, Conditional Access controls, and post-authentication Microsoft 365 access scoping; password reset alone is not enough. 1, 6, 12, 18

4-Executive Summary

Kali365 is a Microsoft 365-focused phishing-as-a-service platform that abuses OAuth device-code authorization to obtain access-token material and bypass normal MFA expectations. Public sources support treating it as a tool/service ecosystem used by multiple criminal users, not as one named threat actor, intrusion set, or campaign. 1, 15, 16, 17

The mechanism is what makes Kali365 different from older fake-login kits. The victim may be sent to Microsoft's real verification page and asked to enter a code that originated from the attacker's workflow. The attacker's objective is authorization and token access, not just a copied password. 1, 5, 18

That design changes the scoping problem. A user can honestly say they used a real Microsoft page and still have participated in an attacker-controlled authorization flow. Responders need to investigate Entra ID sign-ins, device-code events, token issuance, OAuth consent grants, active sessions, mailbox/file access, Teams activity, and Graph/API activity after the suspected authorization. 1, 2, 18

Treat this as an identity incident if users report unsolicited device-code prompts or suspicious cloud-document lures. A password reset can be part of cleanup, but reliable containment requires token/session revocation, sign-out or forced reauthentication, OAuth consent and enterprise app review, Conditional Access assessment, and Microsoft 365 resource-access scoping. 1, 6, 12, 18

Expansion Research Add

Expansion research adds why Kali365 is generating attention: panelized infrastructure, templates, API endpoints, billing/subscription features, and affiliate-style operations make a known technique easier to run and scale. That is different from proving named victims, exact operator identity, or a complete marketplace map. 15, 16, 17

5-AI Agent Delta Updates

6-Why It Matters

7-Timeline

8-How The Tool Works

9-Term Glossary

10-TTPs

13-IOCs / Observables

14-Threat Actor Glossary

17-Exploitable Technology Risks

18-Social Media / Community Signals

16-Decision Ready Actions

12-CVE / Vulnerability References

22-Real World Examples

23-Public Victims / Disclosure Matrix

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

11-Common Questions Q&A

15-Talking Points

21-About the Contributors

26-Source Weighting / Relevance

19-Tier 0 Through Tier 8 Source Summary

20-Source Reconciliation

27-Additional IntelliOS Threat Intel Products on This Topic

28-Notes

29-Citations

30-Version Change Log