Kali365, also referred to as K365 and in some reporting as Octopi365 or Freedom365, is a phishing-as-a-service platform centered on identity compromise, initially focused on Microsoft 365 and Microsoft Entra ID. First observed in 2026, it is marketed largely through Telegram as a turnkey service that lowers the barrier to entry for less technically capable operators by providing phishing templates, campaign automation, real-time dashboards, token capture workflows, and in some cases AI-assisted lure generation and business email compromise support. Kali365 is best known for operationalizing device code phishing against Microsoft’s OAuth 2.0 device authorization flow. In this technique, the operator initiates a legitimate device authorization request and tricks the victim into entering the attacker-provided code on a genuine Microsoft login page. Because the victim authenticates directly with Microsoft, including completing multifactor authentication where required, the attacker can receive valid OAuth access and refresh tokens without stealing the password itself. This enables persistent access to Microsoft 365 resources and can survive simple password resets if tokens or sessions remain valid. Reporting also associates parts of the ecosystem with adversary-in-the-middle capabilities for session cookie theft, token vaulting, mailbox access, and post-compromise session management. Observed Kali365 tradecraft includes Microsoft-themed document-sharing and security-verification lures, multi-stage redirect chains, use of trusted third-party services to increase credibility, anti-bot and anti-analysis protections, and infrastructure rotation through cloud-hosted front ends. Researchers have described multiple panel variants with role-based access, large numbers of API endpoints, built-in lure templates, operator notifications, token management, and self-service subscription workflows. Some variants reportedly include mailbox keyword monitoring, contact harvesting, fraud-oriented email triage, and AI-assisted drafting of replies for business email compromise. Although initially associated with Microsoft 365 token theft, Kali365 has been reported expanding into a broader multi-brand phishing operation. Additional impersonated targets have included Okta, Xerox DocuShare, GMX, LiveDrive, AWS-themed services, and several Russian consumer platforms such as MAX Messenger, Mail.ru, Yandex Disk, and Odnoklassniki. In that broader activity, the operator has been linked not only to OAuth token theft but also to direct credential and one-time-code harvesting workflows, indicating an evolution from a specialized Microsoft device-code phishing kit into a wider account-compromise ecosystem. Kali365 is generally assessed as a financially motivated criminal service rather than a nation-state threat actor. Its significance lies in commoditizing MFA-resistant identity attacks by abusing legitimate authentication workflows instead of relying solely on counterfeit login pages or password theft. Victims have included organizations and users across North America, Europe, and other regions, with targeting spanning enterprise cloud identities and consumer messaging platforms.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another PhaaS platform with similar features to Forg365; no direct connection established in the article.
Phishing-as-a-Service activity associated with OAuth device code phishing targeting Microsoft Entra ID identities.
Conducting Microsoft 365 device-code phishing/account hijacking scams to gain persistent access to victim accounts.
Phishing-as-a-service operation targeting Microsoft accounts by impersonating Microsoft login pages and stealing session cookies and OAuth tokens. The platform supports phishing teams with templates, API endpoints, AI-generated lures, and fraud-enabling email response capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.