ATT&CKReferencesHuntress Kali365 Device Code June 2026

Huntress Kali365 Device Code June 2026

Tanner Flip. (2026, June 11). Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit. Retrieved July 30, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1059.007
JavaScript
MalwareKali365

Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..

T1087.003
Email Account
MalwareKali365

Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.

T1090
Proxy
MalwareKali365

Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.

T1204.001
Malicious Link
MalwareKali365

Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture.

T1204.004
Malicious Copy and Paste
MalwareKali365

Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.

T1550.001
Application Access Token
MalwareKali365

Kali365 has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules.

T1552.001
Credentials In Files
MalwareKali365

Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys.

T1683.001
Written Content
MalwareKali365

Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content. Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.