{"description": "Enterprise techniques used by Kali365, ATT&CK software S9044 (v1.0)", "name": "Kali365 (S9044)", "domain": "enterprise-attack", "versions": {"layer": "4.5", "attack": "19", "navigator": "5.3.2"}, "techniques": [{"techniqueID": "T1087", "showSubtechniques": true}, {"techniqueID": "T1087.003", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.(Citation: Huntress Kali365 Device Code June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1557", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1071", "showSubtechniques": true}, {"techniqueID": "T1071.001", "comment": "[Kali365](https://attack.mitre.org/software/S9044)'s desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1185", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1059", "showSubtechniques": true}, {"techniqueID": "T1059.007", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: Huntress Kali365 Device Code June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1683", "showSubtechniques": true}, {"techniqueID": "T1683.001", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026) [Kali365](https://attack.mitre.org/software/S9044) has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.(Citation: Huntress Kali365 Device Code June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1564", "showSubtechniques": true}, {"techniqueID": "T1564.008", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has the ability to modify email rules to delete email based notifications prior to the victim seeing them.(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1566", "showSubtechniques": true}, {"techniqueID": "T1566.001", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages. (Citation: Artic Wolf Labs Kali365 Device Code April 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1566.002", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has sent bulk phishing emails containing malicious hyperlinks that direct victims to actor-controlled landing pages impersonating services including SharePoint, OneDrive, Teams, DocuSign, and Adobe Acrobat Sign. (Citation: Artic Wolf Labs Kali365 Device Code April 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1090", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has leveraged Cloudflare workers as reverse proxy infrastructure.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1528", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure. (Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1539", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1552", "showSubtechniques": true}, {"techniqueID": "T1552.001", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has searched compromised mailboxes for credential material such as seed phrases and API keys.(Citation: Huntress Kali365 Device Code June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1550", "showSubtechniques": true}, {"techniqueID": "T1550.001", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules.(Citation: Huntress Kali365 Device Code June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1204", "showSubtechniques": true}, {"techniqueID": "T1204.001", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture. (Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Huntress Kali365 Device Code June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1204.004", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: Huntress Kali365 Device Code June 2026)(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1102", "comment": "[Kali365](https://attack.mitre.org/software/S9044) has used Cloudflare Workers to redirect traffic and to host malicious phishing pages.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: Artic Wolf Kali365 Device Code OAuth June 2026)(Citation: SpyCloud Kali365 June 2026) [Kali365](https://attack.mitre.org/software/S9044) has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users.(Citation: Artic Wolf Labs Kali365 Device Code April 2026)(Citation: FBI IC3 Alert I-052126 Kali365 May 2026)(Citation: SpyCloud Kali365 June 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by Kali365", "color": "#66b1ff"}]}