Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..131415
tool
Kali365 S9044
- Type
- malware
- Platforms
- IaaS, macOS, Windows
- Created
- 30 July 2026
- Last modified
- 31 July 2026
Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.[1][2][3][4] Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. [3] Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.[1][5][2][3][4] Kali365 PHaaS was first observed in April 2026.[1] Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.[3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S9044
Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string kali365-live/1.0.0 to access victim mailboxes and enumerate account data following OAuth token capture.16
Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.17
Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.181920
Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages.212223 Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users.212423
Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.27
Standing S9044
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
72nd percentile · 72% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
89th percentile · 89% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
21st percentile · 79% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S9044
283 distinct rules cover the 17 techniques recorded for this tool. The 310 technique-to-rule mappings resolve to 283 distinct rules, because one rule can cover several techniques. 189 Sigma · 94 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org