Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Home/Threats/Kali365 PhaaS Expands to Target Okta and MAX Messenger Users
Threats

Kali365 PhaaS Expands to Target Okta and MAX Messenger Users

Key Takeaways The Kali365 Phishing-as-a-Service (PhaaS) platform has significantly expanded its targeting beyond Microsoft 365. New targets include Okta single sign-on, AWS, Xerox DocuShare,...

Emy Elsamnoudy
Emy Elsamnoudy
June 4, 2026 4 Min Read
56 0

Key Takeaways

  • The Kali365 Phishing-as-a-Service (PhaaS) platform has significantly expanded its targeting beyond Microsoft 365.
  • New targets include Okta single sign-on, AWS, Xerox DocuShare, LiveDrive, GMX, and Russian platforms like MAX Messenger, Mail.ru, Yandex Disk, and Odnoklassniki.
  • The operation leverages a sophisticated phishing kit and abuses Microsoft’s OAuth 2.0 device authorization flow to bypass multi-factor authentication (MFA).
  • A new campaign specifically targets Russian users of MAX Messenger through a “prize claim” phishing scheme to steal credentials and compromise accounts.
  • The FBI previously warned about Kali365, noting its low barrier to entry and advanced features for threat actors, available for approximately $250 per month in Bitcoin.

Kali365 PhaaS Expands Reach, Targets Okta and MAX Messenger Users

The Kali365 Phishing-as-a-Service (PhaaS) platform, initially identified in April 2026 for its focus on stealing Microsoft 365 credentials, has dramatically broadened its malicious operations. Recent analysis reveals a significant expansion, now encompassing major platforms such as Okta single sign-on systems, the Russian messaging service MAX Messenger, and numerous other online services.

Table Of Content

  • Key Takeaways
  • Kali365 PhaaS Expands Reach, Targets Okta and MAX Messenger Users
  • Arctic Wolf Uncovers Expanded Infrastructure and New Campaigns
  • Multi-Brand Phishing Operations and MAX Messenger Campaign
  • What You Should Do

Kali365 operates by exploiting a legitimate Microsoft login mechanism: the OAuth 2.0 device authorization flow. This protocol was designed for devices with limited input capabilities, like smart TVs, to facilitate secure logins. The PhaaS platform abuses this by generating a valid Microsoft login code, embedding it within deceptive document-sharing pages, and then prompting victims to enter this code on the genuine Microsoft website. This method allows attackers to obtain a functional login token without requiring the victim’s password or multi-factor authentication (MFA) code, effectively bypassing conventional security measures.

Arctic Wolf Uncovers Expanded Infrastructure and New Campaigns

Cybersecurity researchers at Arctic Wolf have extensively tracked the Kali365 operation, mapping its full scope and capabilities. In a report shared with Cyber Security News (CSN), Arctic Wolf stated, “Arctic Wolf has observed a significant expansion of the phishing-as-a-service operation Kali365, which abuses Microsoft’s OAuth device authorization flow to bypass MFA.”

Their investigation led to the discovery of a live command-and-control (C2) panel, a phishing cluster comprising 126 hosts, and a new, targeted attack campaign aimed at Russian users via the MAX Messenger, a state-backed application with over 110 million registered users.

The FBI had previously issued a public warning about Kali365 in May 2026, highlighting its accessibility and advanced features. The platform is offered on Telegram for approximately $250 per month, payable in Bitcoin, making it an attractive and potent tool for a broad spectrum of threat actors.

Multi-Brand Phishing Operations and MAX Messenger Campaign

The same operator responsible for the initial Microsoft 365 attacks has now diversified into a multi-brand phishing operation. Researchers have identified 126 malicious hosts, all utilizing the same phishing kit, impersonating a wide array of services. These include Okta SSO, Xerox DocuShare, LiveDrive, AWS, GMX, and prominent Russian platforms such as Mail.ru, Yandex Disk, and Odnoklassniki. This indicates a single, cohesive infrastructure rotating through numerous brand disguises rather than disparate threats.

A particularly notable development is the campaign targeting MAX Messenger users. Attackers have established a fraudulent “prize claim” page, greatness-marketing[.]top, designed to mimic a legitimate prize verification site. Victims are instructed to input their Russian phone number, followed by a genuine one-time password (OTP) from MAX Messenger, and then a two-factor authentication (2FA) code. All this sensitive information is relayed to the attacker in real-time via a Telegram bot identified as @NovosibyrskyMoneyBot.

Upon successful compromise of a MAX Messenger account, the attacker gains full access to messages, media files, and the victim’s entire contact list. This contact list then becomes the source for the next wave of attacks, as the compromised account automatically propagates the same “prize lure” to all its contacts. This propagation model mirrors established scam tactics prevalent on Telegram but is now being deployed at the massive scale of one of the largest messaging platforms in the Russian-speaking world.

What You Should Do

  • Block Malicious Infrastructure: Immediately block outbound connections from your network to panel[.]securehubcloud[.]com. This is a confirmed Kali365 command-and-control (C2) address. Set up alerts for any attempted connections to this domain.
  • Block Associated Domains: Block the entire attachedfile[.]com domain family, as all 39 observed subdomains are serving the Kali365 phishing kit.
  • Disable Microsoft 365 Device Code Flow: For Microsoft 365 environments, consider disabling the OAuth 2.0 device code authentication flow via a Conditional Access policy. This is a highly effective mitigation against this specific attack vector.
  • Monitor for Post-Authentication Anomalies: Implement monitoring for unusual post-authentication behaviors, such as mass contact exports, unusual inbox access patterns, or logins from unfamiliar geographic locations.
  • Enhance Security Awareness Training: Continuously educate users on recognizing sophisticated phishing attempts, especially unexpected login prompts or “prize claim” notifications. Emphasize the importance of verifying URLs and never entering credentials on suspicious sites.
  • Review Indicators of Compromise (IoCs): Integrate the provided IoCs into your threat intelligence platforms and security information and event management (SIEM) systems for proactive detection and blocking. Remember to “re-fang” defanged indicators only within controlled environments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Payouts King Ransomware Evades EDR via Obfuscation and Direct System Calls

Next Post

Fake ChatGPT Site Spreads Malware Through Google Ads

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us