Home Blog Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit Published: June 11, 2026 Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit By: Tanner Filip Summarize with AI Summarize ChatGPT Claude Perplexity Google AI Key Takeaways Huntress traced unusual device code authentication activity from Tencent Cloud to a suspected Kali365 campaign and identified a much larger footprint behind it, including more than 240 IPs hosting multiple panel variants. The kit is far more than a phishing page. Huntress found a full Phishing-as-a-Service (PhaaS) ecosystem with at least 33 built-in lure templates, 100+ API endpoints, RBAC, billing, a domain marketplace, and multiple editions tailored for different operator goals. The attack flow is fast and effective: victims are pushed through a legitimate Microsoft login and prompted to enter a device code, giving attackers access that can persist even after MFA use or password changes. Kali365’s post-compromise features show how quickly phishing is being operationalized for fraud. One edition includes AI-assisted BEC drafting, high-value email triage, credential scanning, and Exchange admin abuse to turn stolen access into monetizable outcomes. The companion desktop apps, such as OctoLink Live and OctoLink Sender, make the threat harder to catch because they convert stolen tokens into real browser sessions and controlled outbound phishing activity that can blend in with normal tenant behavior. That means defenders need to hunt across sign-in logs, token activity, mailbox abuse, unusual user agents, and suspicious infrastructure together. Kali365, Octopi365, and Freedom365 are related names for the same Phishing-as-a-Service platform, likely stemming from rebranding, kit theft, or other operator activities. Disclosure: AI assistance was used for parts of this blog post and analysis. Acknowledgments: Special thanks to Lindsey O’Donnell-Welch and Matt Anderson for their contributions to this investigation and write-up. TL;DR In mid-May, the Huntress SOC observed device code authentication events that, upon further investigation, led to a suspected Kali365 / Octopi365 PhaaS operation. What I found was not just a single phishing page or simple credential theft play. The activity pointed to a broader, more mature ecosystem built to capture tokens, maintain access, abuse compromised mailboxes, and support follow-on fraud. That included multiple panel variants, built-in lure templates, token management, AI-assisted business email compromise (BEC) features, and companion desktop apps that could turn stolen access into real browser sessions and outbound phishing activity. Along the way, the investigation also surfaced behavior consistent with tactics Microsoft previously described in its Storm-2372 reporting , including use of the Microsoft Authentication Broker client ID to obtain refresh tokens that can support downstream device registration and email access. Suspicious device code activity can be the front door to a much larger post-compromise problem, and these events should be investigated as a sign of broader token abuse, mailbox access, persistence, and related infrastructure activity, not written off as a one-off phishing lure or isolated sign-in anomaly. This blog provides a closer look at the attack chain, victim experience, phishing infrastructure, and operator tooling behind the campaign. Background Beginning on May 18, 2026, the Huntress SOC started to observe device code authentication events from Tencent Cloud IP addresses in AS132203. This hit its apex on May 20, with over 80 successful ‘UserLoggedIn’ events. Figure 1: Device code authentication events from Tencent Cloud IP addresses (May 18 - 27) This type of influx made me think there was some new sort of campaign going on, so I dug in. What I discovered was that this was a fairly new PhaaS kit known as Kali365. Similar to our reporting on EvilTokens earlier this year, this phishing kit uses the device authentication code flow to trick users into letting them into environments, and keeping access even if MFA is used and passwords are changed post-compromise. SOC analysts when they saw users logging in from Tencent Cloud en masse (Credit: @vxunderground) This would take me on quite a hunt. Using Validin, we were able to find over 150 IP addresses hosting several variants of this phishing kit panel. A majority of them were one variant hosted on Tencent Cloud, but a deeper investigation unveiled a whole ecosystem. But first, we’ll take a few steps back to look at the attack itself. The phishing expedition In at least one case, users received emails leading them to a website hosted on Canva, claiming that the email was encrypted. Figure 2: Canva-hosted website Further analysis of this website shows that once targets click on the big “CLICK HERE” button (in Figure 2), they are taken to a fairly legitimate-looking webpage that gives them a code. Figure 3: A code is shared with targets as part of the attack Clicking “View” opens a legitimate Microsoft login page. Figure 4: Targets are prompted to log in and then enter the code Once the user logs in, they’re prompted to enter the code that is given to them. If the code is entered, the attacker is in, and the user is redirected to a webpage that simply says “Document Expired”. In as little as 42 seconds, the attacker has gained persistent access. Figure 5: Browser history from the endpoint of a victim to this attack A new foe has appeared: Kali365 (and Octopi365?) Kali365 is a newer AI-enabled phishing kit, according to the FBI , it was first observed in April 2026. This vibe-coded PhaaS panel has several variants, and a couple different names. At this time, it’s unclear why there are multiple names. Before going any further, some clarification on all the names that we’ve observed with this platform. The most widely used name we’ve seen so far is “Kali365”. Some pivoting using Validin led us to identical panels with the name “Octopi365”. This name was also referenced in one of the executables (we’ll talk about that later) that we found on VirusTotal. A third name that we found hosting a panel was “Freedom365”, but that one seems to have been more short-lived. They are all related, but it’s unclear if this is due to rebranding, kits being stolen, or some other sort of shenanigans by the operators. The panels are React-based single-page applications. That means we were able to take a look behind the scenes just by hitting F12. We discovered at least three variants, each with different capabilities. With the help of our AI overlord assistant, we went through nearly 100,000 lines of JavaScript (most of which was just imported libraries) to figure out what each variant could do. What we discovered was that Kali365 (or is it Octopi365?) is a fully-featured PhaaS kit with at least 33 different lures built-in, over 100 API endpoints, RBAC, a full payout pipeline, self-service payments through cryptocurrency payment gateway OxaPay, and a desktop application for operators - a whole cybercrime ecosystem. We analyzed three different “editions” of this, which will (arbitrarily) be called E1, E2, and E3. These names don’t imply that one is “higher” than others, it’s just the order in which they were analyzed. Common themes Among the three editions were a few commonalities. Each has the same 33 phishing lure templates built-in. In some variations, some of the lures are labeled as “pro”, suggesting there may be a tier system. Name Description Pro Feature OneDrive File sharing No SharePoint Document library No SharePoint Site Team site No Teams Message / meeting No Outlook Email portal No OneNote Shared notebook No DocuSign Document signing No Adobe PDF review No Dropbox File download No Google Drive File access No Voicemail Missed voicemail No Direct Login Clean Microsoft sign-in No Admin Center M365 admin Yes Security Alert Account security Yes Password Reset Password reset Yes MFA Setup MFA enrollment Yes Quarantine Email quarantine Yes Teams Meeting Meeting invite Yes Teams Approval Approval request Yes Forms Survey / form Yes Planner Task assignment Yes Calendar Calendar event Yes Loop Collaborative workspace Yes Copilot AI assistant Yes To Do Task notification Yes OneDrive Business Business share Yes SharePoint News News article Yes Power Automate Workflow Yes Intune Device enrollment Yes Yammer Community post Yes Sway Interactive report Yes Stream Video notification Yes Whiteboard Collaborative board Yes Bookings Appointment booking Yes Also common among the three was a number of frontend routes (React-talk for “page”). The full list is in Appendix A From just these endpoints, we can get a good amount of interesting information. First, the “keywords” endpoint suggests that operators can add specific keywords to monitor once they’re in a victim’s account. Phrases like “invoice”, “wire transfer”, “payment”, etc. are common ones for attackers to intercept. The /domains route, combined with some of the API endpoints we found, show that the panel has a whole marketplace built in. It's a credit-based in-panel domain reseller; purchased domains feed directly into the CF-Worker linking pipeline. Operators can buy a domain and use it in their lures, all without leaving the comfort of their panels. Kali365 variants E1 E1 is the one we saw mostly on Tencent, and is the base configuration of the panel: a React/Vite single-page app that captures Microsoft 365 sessions using Adversary-in-the-Middle (AiTM) reverse-proxy cookie theft and Device Code flow lures. Operators can access these sessions through a token vault, a library of 33 lure templates, and a built-in Outlook webmail proxy at /dash/outlook/{id} , which allows them to read victim mailboxes directly in the panel. Operators receive capture notifications through a configured Telegram bot. Lure traffic is routed through Cloudflare Workers with linked custom domains, and Cloudflare
The article details the Kali365/Octopi365 Phishing-as-a-Service (PhaaS) platform, which uses device code phishing to steal Microsoft authentication tokens, granting attackers persistent access that can survive MFA and password resets. The ecosystem includes over 240 IPs hosting management panels, numerous lure templates, and companion desktop applications that convert stolen tokens into live browser sessions to conduct Business Email Compromise (BEC) and blend malicious activity into normal tenant traffic. The article advises defenders to hunt across sign-in logs, token activity, mailbox abuse, and suspicious infrastructure, as no specific software vulnerability, CVSS score, or patch is discussed.