Kali365, also referred to as K365 and in some reporting associated with Octopi365 and Freedom365 branding, is a phishing-as-a-service platform focused on identity compromise and account takeover. First observed in 2026, it became notable for operationalizing Microsoft OAuth device-code phishing against Microsoft 365 and Entra ID users. In this workflow, operators or affiliates initiate a legitimate device authorization request and trick victims into entering the attacker-provided code on a genuine Microsoft login page. Because the victim completes normal authentication and any required MFA, the attacker receives valid OAuth tokens tied to the authorized session rather than needing to steal the password directly. This enables persistent access to cloud resources such as Outlook, OneDrive, SharePoint, and Teams until tokens are revoked or expire, and can survive password resets if token/session revocation is not also performed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a prior device code phishing tool for comparison.
Device-code phishing campaign abusing Microsoft's legitimate authentication flow to obtain OAuth tokens for persistent passwordless cloud access.
A phishing-as-a-service operation productizing device-code phishing against Microsoft identity flows, offering lure generation, templates, dashboards, OAuth-token capture, tenant validation, reconnaissance, and persistence capabilities.
Mentioned as a possible alignment/comparison point for device code phishing and token abuse campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.