Kali365, also referred to as K365 and in some reporting as Octopi365 or Freedom365, is a phishing-as-a-service (PhaaS) operation focused on identity compromise and account takeover. First observed in 2026, it is marketed primarily through Telegram and lowers the barrier to entry for criminal affiliates by providing hosted phishing infrastructure, ready-made lures, campaign templates, victim tracking dashboards, and token-capture workflows. Kali365 is best known for abusing Microsoft OAuth 2.0 device authorization flow against Microsoft 365 and Microsoft Entra ID users. In this technique, victims are lured into entering an attacker-supplied device code on a legitimate Microsoft authentication page and completing normal sign-in and multifactor authentication. The result is issuance of OAuth tokens to the attacker-controlled session rather than direct theft of the victim’s password. This enables persistent access to Microsoft 365 resources such as mail, files, collaboration platforms, and other connected cloud services, and can remain effective even after password changes until tokens and related persistence are fully remediated. The platform has also been associated with adversary-in-the-middle capabilities, session and cookie theft, token vaulting, mailbox access, phishing template management, and operational tooling for large-scale phishing campaigns. Reported panel variants have included features such as role-based access, affiliate-style workflows, automated notifications, contact harvesting, keyword monitoring in compromised mailboxes, and AI-assisted business email compromise functions that analyze intercepted conversations and draft fraudulent replies. Companion tooling has been reported for converting stolen tokens into live browser sessions and for sending phishing messages through compromised Microsoft 365 accounts. Although initially centered on Microsoft-themed device-code phishing, Kali365 has expanded into a broader multi-brand phishing operation. Observed impersonation and targeting have included enterprise identity and document-sharing services such as Okta, Xerox DocuShare, LiveDrive, GMX, and AWS-themed services, as well as Russian consumer platforms including Mail.ru, Yandex Disk, Odnoklassniki, and MAX Messenger. The MAX Messenger activity used a different workflow from Microsoft device-code phishing, collecting phone numbers, one-time codes, and optional two-factor authentication passwords to take over accounts and propagate further phishing through compromised contact lists. Victimology includes U.S. organizations and broader enterprise targets across North America and Europe, with reporting also indicating targeting of financial and operational personnel using payment and remittance themes. The operation has been linked to large-scale phishing activity and is part of a wider rise in commodity device-code phishing ecosystems alongside other PhaaS offerings. Public warnings from the FBI have highlighted Kali365 as an emerging criminal service that can bypass MFA protections by exploiting legitimate authentication workflows rather than spoofing login pages. Kali365 should be understood as a financially motivated criminal phishing service rather than a confirmed nation-state actor. Its significance lies in operationalizing token theft and MFA bypass at scale through legitimate OAuth flows, trusted-brand impersonation, cloud-hosted infrastructure, and increasingly mature affiliate and automation features.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A subscription phishing platform distributed mainly through Telegram that enables affiliates to run multi-brand phishing campaigns. Its best-documented technique abuses Microsoft OAuth device-code flow to capture access and refresh tokens, and it has also expanded to impersonate services such as Google Workspace, Okta, AWS-themed services, Xerox DocuShare, LiveDrive, GMX, Mail.ru, Yandex Disk, Odnoklassniki, and MAX Messenger.
A phishing-as-a-service operation using Microsoft device code phishing to trick victims into authorizing attacker-controlled devices on legitimate Microsoft authentication pages, enabling theft of OAuth access and refresh tokens for persistent access to Microsoft 365 resources.
Mentioned only as another PhaaS platform with similar features to Forg365; no direct connection established in the article.
Phishing-as-a-Service activity associated with OAuth device code phishing targeting Microsoft Entra ID identities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.