Skip to content

Kali365

Profile source: Mallory opens in a new tab

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 8, 2026
Feed role
C2 / Distribution
Host form
0 IP / 64 hostnames

Leading locations

  • US54
  • CA1
  • SE1

Leading providers

  • Cloudflare, Inc.50
  • Amazon.com, Inc.4
  • Team Internet AG1
  • Telia Company AB1

Infrastructure traits

  • Hosting 55
  • Anycast 53
  • Proxy 6
  • Vpn 1

Reported operators

Threat actors

1 named in public reporting
Storm-2372

What I discovered was that this was a fairly new PhaaS kit known as Kali365. Similar to our reporting on EvilTokens earlier this year, this phishing kit uses the device authentication code flow to trick users into letting them into environments, and keeping access even if MFA is used and passwords are changed post-compromise.

MITRE ATT&CK

Kali365 in ATT&CK

23 distinct techniques

Reporting

Research mentioning Kali365

Jul 23
Knowbe4

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.

Jul 22
Cyber Security News

Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions

Attackers ran a procurement-themed adversary-in-the-middle phishing campaign against universities, enterprises, multinational institutions, and organizations linked to the European Union and United Nations, using compromised Outlook accounts to resend lures from trusted internal or partner addresses. Victims were directed to fake document download portals with CAPTCHA stages and cloned Microsoft 365 login pages impersonating brands including Microsoft, OpenGov, ConstructConnect, and the European Investment Bank, enabling the theft of credentials, session cookies, and MFA-authenticated tokens in real time. Researchers said the operation relied on reverse-proxy phishing kits including EvilProxy, FlowerStorm/Storm-1167, and Kali365 to bypass MFA and gain access to Outlook, SharePoint, and other Microsoft 365 resources. The infrastructure favored aged or compromised domains, RDGA-style phishing domains, phishing subdomain conventions, and injected PHP content on dormant websites, indicating an effort to evade detection by avoiding newly registered infrastructure; defenders were urged to use DNS and passive DNS visibility, Microsoft 365 sign-in monitoring, and conditional access controls because MFA alone does not stop session hijacking.

Jul 21
Infoblox Threat Intel

Inside a Global Procurement-Themed AiTM Phishing Campaign

Jul 18
Infosec Writeups

Medium

Jul 15
Techrepublic Com Security

Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts

Jul 14
ReliaQuest

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

Jul 14
Bleeping Computer

New phishing kits target Microsoft 365 accounts, evade MFA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.