S9044: Kali365
Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.[1][2][3][4] Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. [3] Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.[1][5][2][3][4] Kali365 PHaaS was first observed in April 2026.[1] Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.[3]
Security context for executives and security teams
S9044: Kali365 describes [Kali365](https://attack.mitre.org/software/S9044) is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) [Kali365](https://attack.mitre.org/software/S...
Executive priority
S9044: Kali365 is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S9044: Kali365 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (IaaS, macOS, Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Cloud control-plane, SaaS audit, and container platform logs
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S9044: Kali365 appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Kali365
Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.[1][2][3][4] Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. [3] Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.[1][5][2][3][4] Kali365 PHaaS was first observed in April 2026.[1] Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.[3]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1204.004 | Malicious Copy and PasteSub-technique | |
| Enterprise | T1557 | Adversary-in-the-Middle | |
| Enterprise | T1102 | Web Service | |
| Enterprise | T1090 | Proxy | |
| Enterprise | T1683.001 | Written ContentSub-technique | Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content.[1][5][2][3] Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.[3] |
| Enterprise | T1539 | Steal Web Session Cookie | |
| Enterprise | T1185 | Browser Session Hijacking | |
| Enterprise | T1552.001 | Credentials In FilesSub-technique | |
| Enterprise | T1550.001 | Application Access TokenSub-technique | |
| Enterprise | T1059.007 | JavaScriptSub-technique | Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..[1][5][3] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | |
| Enterprise | T1528 | Steal Application Access Token | |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1204.001 | Malicious LinkSub-technique | |
| Enterprise | T1564.008 | Email Hiding RulesSub-technique | |
| Enterprise | T1087.003 | Email AccountSub-technique |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | 0a6c7f978097… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Artic Wolf Labs Kali365 Device Code April 2026
Artic Wolf Labs. (2026, April 24). Token Bingo: Don’t Let Your Code be the Winner. Retrieved July 30, 2026.
Open source URL - [2]FBI IC3 Alert I-052126 Kali365 May 2026
Federal Bureau of Investigation. (2026, May 21). Alert Number: I-052126-PSA: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens. Retrieved July 30, 2026.
Open source URL - [3]Huntress Kali365 Device Code June 2026
Tanner Flip. (2026, June 11). Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit. Retrieved July 30, 2026.
Open source URL - [4]SpyCloud Kali365 June 2026
Trevor Hilligoss. (2026, June 11). Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit – From Telegram Hype to FBI Takedown Theater. Retrieved July 30, 2026.
Open source URL - [5]Artic Wolf Kali365 Device Code OAuth June 2026
Artic Wolf Labs. (2026, June 2). Retrieved July 30, 2026.
Open source URL - [6]mitre-attackS9044Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
