Kali365 PhaaS Expands to Target Okta and MAX Messenger Users
Key Takeaways The Kali365 Phishing-as-a-Service (PhaaS) platform has significantly expanded its targeting beyond Microsoft 365. New targets include Okta single sign-on, AWS, Xerox DocuShare,...
Key Takeaways
- The Kali365 Phishing-as-a-Service (PhaaS) platform has significantly expanded its targeting beyond Microsoft 365.
- New targets include Okta single sign-on, AWS, Xerox DocuShare, LiveDrive, GMX, and Russian platforms like MAX Messenger, Mail.ru, Yandex Disk, and Odnoklassniki.
- The operation leverages a sophisticated phishing kit and abuses Microsoft’s OAuth 2.0 device authorization flow to bypass multi-factor authentication (MFA).
- A new campaign specifically targets Russian users of MAX Messenger through a “prize claim” phishing scheme to steal credentials and compromise accounts.
- The FBI previously warned about Kali365, noting its low barrier to entry and advanced features for threat actors, available for approximately $250 per month in Bitcoin.
Kali365 PhaaS Expands Reach, Targets Okta and MAX Messenger Users
The Kali365 Phishing-as-a-Service (PhaaS) platform, initially identified in April 2026 for its focus on stealing Microsoft 365 credentials, has dramatically broadened its malicious operations. Recent analysis reveals a significant expansion, now encompassing major platforms such as Okta single sign-on systems, the Russian messaging service MAX Messenger, and numerous other online services.
Table Of Content
Kali365 operates by exploiting a legitimate Microsoft login mechanism: the OAuth 2.0 device authorization flow. This protocol was designed for devices with limited input capabilities, like smart TVs, to facilitate secure logins. The PhaaS platform abuses this by generating a valid Microsoft login code, embedding it within deceptive document-sharing pages, and then prompting victims to enter this code on the genuine Microsoft website. This method allows attackers to obtain a functional login token without requiring the victim’s password or multi-factor authentication (MFA) code, effectively bypassing conventional security measures.
Arctic Wolf Uncovers Expanded Infrastructure and New Campaigns
Cybersecurity researchers at Arctic Wolf have extensively tracked the Kali365 operation, mapping its full scope and capabilities. In a report shared with Cyber Security News (CSN), Arctic Wolf stated, “Arctic Wolf has observed a significant expansion of the phishing-as-a-service operation Kali365, which abuses Microsoft’s OAuth device authorization flow to bypass MFA.”
Their investigation led to the discovery of a live command-and-control (C2) panel, a phishing cluster comprising 126 hosts, and a new, targeted attack campaign aimed at Russian users via the MAX Messenger, a state-backed application with over 110 million registered users.
The FBI had previously issued a public warning about Kali365 in May 2026, highlighting its accessibility and advanced features. The platform is offered on Telegram for approximately $250 per month, payable in Bitcoin, making it an attractive and potent tool for a broad spectrum of threat actors.
Multi-Brand Phishing Operations and MAX Messenger Campaign
The same operator responsible for the initial Microsoft 365 attacks has now diversified into a multi-brand phishing operation. Researchers have identified 126 malicious hosts, all utilizing the same phishing kit, impersonating a wide array of services. These include Okta SSO, Xerox DocuShare, LiveDrive, AWS, GMX, and prominent Russian platforms such as Mail.ru, Yandex Disk, and Odnoklassniki. This indicates a single, cohesive infrastructure rotating through numerous brand disguises rather than disparate threats.
A particularly notable development is the campaign targeting MAX Messenger users. Attackers have established a fraudulent “prize claim” page, greatness-marketing[.]top, designed to mimic a legitimate prize verification site. Victims are instructed to input their Russian phone number, followed by a genuine one-time password (OTP) from MAX Messenger, and then a two-factor authentication (2FA) code. All this sensitive information is relayed to the attacker in real-time via a Telegram bot identified as @NovosibyrskyMoneyBot.
Upon successful compromise of a MAX Messenger account, the attacker gains full access to messages, media files, and the victim’s entire contact list. This contact list then becomes the source for the next wave of attacks, as the compromised account automatically propagates the same “prize lure” to all its contacts. This propagation model mirrors established scam tactics prevalent on Telegram but is now being deployed at the massive scale of one of the largest messaging platforms in the Russian-speaking world.
What You Should Do
- Block Malicious Infrastructure: Immediately block outbound connections from your network to
panel[.]securehubcloud[.]com. This is a confirmed Kali365 command-and-control (C2) address. Set up alerts for any attempted connections to this domain. - Block Associated Domains: Block the entire
attachedfile[.]comdomain family, as all 39 observed subdomains are serving the Kali365 phishing kit. - Disable Microsoft 365 Device Code Flow: For Microsoft 365 environments, consider disabling the OAuth 2.0 device code authentication flow via a Conditional Access policy. This is a highly effective mitigation against this specific attack vector.
- Monitor for Post-Authentication Anomalies: Implement monitoring for unusual post-authentication behaviors, such as mass contact exports, unusual inbox access patterns, or logins from unfamiliar geographic locations.
- Enhance Security Awareness Training: Continuously educate users on recognizing sophisticated phishing attempts, especially unexpected login prompts or “prize claim” notifications. Emphasize the importance of verifying URLs and never entering credentials on suspicious sites.
- Review Indicators of Compromise (IoCs): Integrate the provided IoCs into your threat intelligence platforms and security information and event management (SIEM) systems for proactive detection and blocking. Remember to “re-fang” defanged indicators only within controlled environments.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.