Kali365 — Malware Profile
Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution. Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover. Kali365 PHaaS was first observed in April 2026. Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.
MITRE ATT&CK techniques (17)
- T1059.007 JavaScript
- T1071.001 Web Protocols
- T1087.003 Email Account
- T1090 Proxy
- T1102 Web Service
- T1185 Browser Session Hijacking
- T1204.001 Malicious Link
- T1204.004 Malicious Copy and Paste
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1550.001 Application Access Token
- T1552.001 Credentials In Files
- T1557 Adversary-in-the-Middle
- T1564.008 Email Hiding Rules
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1683.001 Written Content