Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 124 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
fa1ddd39e231b4b6d4bdf7346c561e94cbeaddc0f6de7c1bc1c3d890b27e23ab d3c0f5b71d725c107bb013af3f682fe1aaaf2502c8cc2b900920cf20b2401130 a70d5626f7bb0f70de46ca2d65caa49d03cc05f14e2ce611b772f91c828e492b 0886359456d54669c632372b1efe6238f6a5c782df8b133913c2265c2502ff9d 12540b34f7aedbae88bd1cf68ab0a54873aa23cec346ea836dcc59532d3bfbb2 1661d124d96d847ae844c3f44ac5c7a873b3fa4943f3a13a36097fec8add9d55 2e8533ba33b7c8990e91008f94d85f32ae8b2268052b4725b649eb0cf936f33c 47a3c726bc30159998e4bdb13ab1894c1f4c2537ebec98d3655136a0503c1838 75373bb40b487757387433385fd1f20bcf786cb94e84dd036730562386556055 7fd96e76638bc041ce32a6ff318484a6604fbb82143891139e240e5d7174f262 Reported operators
What I discovered was that this was a fairly new PhaaS kit known as Kali365. Similar to our reporting on EvilTokens earlier this year, this phishing kit uses the device authentication code flow to trick users into letting them into environments, and keeping access even if MFA is used and passwords are changed post-compromise.
MITRE ATT&CK
Reporting
Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victimsโ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.
Attackers ran a procurement-themed adversary-in-the-middle phishing campaign against universities, enterprises, multinational institutions, and organizations linked to the European Union and United Nations, using compromised Outlook accounts to resend lures from trusted internal or partner addresses. Victims were directed to fake document download portals with CAPTCHA stages and cloned Microsoft 365 login pages impersonating brands including Microsoft, OpenGov, ConstructConnect, and the European Investment Bank, enabling the theft of credentials, session cookies, and MFA-authenticated tokens in real time. Researchers said the operation relied on reverse-proxy phishing kits including EvilProxy, FlowerStorm/Storm-1167, and Kali365 to bypass MFA and gain access to Outlook, SharePoint, and other Microsoft 365 resources. The infrastructure favored aged or compromised domains, RDGA-style phishing domains, phishing subdomain conventions, and injected PHP content on dormant websites, indicating an effort to evade detection by avoiding newly registered infrastructure; defenders were urged to use DNS and passive DNS visibility, Microsoft 365 sign-in monitoring, and conditional access controls because MFA alone does not stop session hijacking.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.