ATT&CKReferencesSpyCloud Kali365 June 2026

SpyCloud Kali365 June 2026

Trevor Hilligoss. (2026, June 11). Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit – From Telegram Hype to FBI Takedown Theater. Retrieved July 30, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1090
Proxy
MalwareKali365

Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.

T1102
Web Service
MalwareKali365

Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users.

T1204.004
Malicious Copy and Paste
MalwareKali365

Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.

T1528
Steal Application Access Token
MalwareKali365

Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure.

T1539
Steal Web Session Cookie
MalwareKali365

Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.

T1557
Adversary-in-the-Middle
MalwareKali365

Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.

T1564.008
Email Hiding Rules
MalwareKali365

Kali365 has the ability to modify email rules to delete email based notifications prior to the victim seeing them.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.