ATT&CKReferencesArtic Wolf Labs Kali365 Device Code April 2026

Artic Wolf Labs Kali365 Device Code April 2026

Artic Wolf Labs. (2026, April 24). Token Bingo: Don’t Let Your Code be the Winner. Retrieved July 30, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1059.007
JavaScript
MalwareKali365

Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..

T1071.001
Web Protocols
MalwareKali365

Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture.

T1090
Proxy
MalwareKali365

Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.

T1102
Web Service
MalwareKali365

Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users.

T1185
Browser Session Hijacking
MalwareKali365

Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.

T1204.001
Malicious Link
MalwareKali365

Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture.

T1204.004
Malicious Copy and Paste
MalwareKali365

Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.

T1528
Steal Application Access Token
MalwareKali365

Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure.

T1539
Steal Web Session Cookie
MalwareKali365

Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.

T1557
Adversary-in-the-Middle
MalwareKali365

Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.

T1566.001
Spearphishing Attachment
MalwareKali365

Kali365 has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages.

T1566.002
Spearphishing Link
MalwareKali365

Kali365 has sent bulk phishing emails containing malicious hyperlinks that direct victims to actor-controlled landing pages impersonating services including SharePoint, OneDrive, Teams, DocuSign, and Adobe Acrobat Sign.

T1683.001
Written Content
MalwareKali365

Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content. Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.