Kali365
MITREOther
Unknown
Unknown
[Kali365](https://attack.mitre.org/software/S9044) is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) [Kali365](https://attack.mitre.org/software/S9044) incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. (Citation: Huntress Kali365 Device Code June 2026) Operators have used [Kali365](https://attack.mitre.org/software/S9044) to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026) [Kali365](https://attack.mitre.org/software/S9044) PHaaS was first observed in April 2026.(Citation: Artic Wolf Labs Kali365 Device Code April 2026) [Kali365](https://attack.mitre.org/software/S9044) has also been affiliated with other branding to include Octopi365 and Freedom365.(Citation: Huntress Kali365 Device Code June 2026)
Associated Techniques (17)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1059.007 | JavaScript | - |
| T1071.001 | Web Protocols | - |
| T1087.003 | Email Account | - |
| T1090 | Proxy | - |
| T1102 | Web Service | - |
| T1185 | Browser Session Hijacking | - |
| T1204.001 | Malicious Link | - |
| T1204.004 | Malicious Copy and Paste | - |
| T1528 | Steal Application Access Token | - |
| T1539 | Steal Web Session Cookie | - |
| T1550.001 | Application Access Token | - |
| T1552.001 | Credentials In Files | - |
| T1557 | Adversary-in-the-Middle | - |
| T1564.008 | Email Hiding Rules | - |
| T1566.001 | Spearphishing Attachment | - |
Metadata
| ID: | 327647 |
| Created: | 06/08/2026 04:00 |
| Updated: | 09/08/2026 04:00 |