Kali365 Phishing Platform Turns Microsoft Logins Into an AI-Powered Fraud Pipeline
- Jun 11
- 2 min read
The phishing-as-a-service operation uses Microsoft device codes, stolen authentication tokens and AI-generated business email compromise messages to help attackers bypass traditional account defenses.
A newly analyzed phishing platform known as Kali365 is giving cybercriminals an unusually complete toolkit for compromising Microsoft 365 accounts and converting stolen access into financial fraud.
Huntress researchers uncovered the operation after detecting a spike in device code authentication events originating from Tencent Cloud infrastructure in May. The investigation ultimately identified more than 240 IP addresses associated with several versions of the platform, which has also appeared under the names Octopi365 and Freedom365.
Unlike conventional phishing kits that simply collect usernames and passwords, Kali365 targets authentication tokens. Victims are directed through a legitimate Microsoft sign-in page and instructed to enter a device code supplied by the attacker. Once the user approves the request, the criminal can gain persistent access to the account, potentially surviving password resets and completed multifactor authentication challenges.
In one observed attack, the entire compromise took as little as 42 seconds.
A Full-Service Cybercrime Platform
Huntress found at least 33 built-in phishing templates impersonating services such as OneDrive, SharePoint, Teams, Outlook, DocuSign and Microsoft Copilot. The platform also contains more than 100 API endpoints, role-based access controls, cryptocurrency payments and a marketplace where operators can purchase domains for new campaigns.
Different editions appear to serve separate criminal business models. One version focuses on capturing and managing Microsoft 365 sessions. Another is designed for post-compromise fraud, including mailbox scanning, credential discovery and Exchange administration abuse. A third supports subscriptions and reseller operations, allowing new customers to pay with cryptocurrency and provision accounts with little or no human oversight.
The most advanced version includes an AI-assisted business email compromise module. According to Huntress, the tool can analyze intercepted conversations, identify high-value payment or payroll threads and prepare contextual replies that redirect wire transfers or invoices.
The researchers said the module’s code referenced Claude Sonnet as the model used to evaluate messages and generate fraudulent drafts.
Stolen Tokens Become Real Browser Sessions
Kali365 is also supported by desktop tools called OctoLink Live and OctoLink Sender.
OctoLink Live converts captured tokens into authenticated Chromium sessions for Outlook, OneDrive, SharePoint and Microsoft administration portals. This makes malicious activity resemble normal browser use rather than automated access through Microsoft Graph, complicating detection.
OctoLink Sender supports lateral phishing by sending messages from compromised accounts. It can create drafts, send them and remove or verify artifacts in patterns intended to maintain control over outbound campaigns.
For security teams, the research shows why a successful device code login should not be treated as an isolated authentication anomaly. Defenders may need to correlate sign-in records with token refresh activity, unusual browser identifiers, suspicious mailbox behavior, newly created mail-flow rules and infrastructure linked to phishing domains.
Kali365 reflects a broader shift in the phishing economy. Criminal groups are no longer selling only fake login pages. They are packaging authentication theft, persistent access, AI-assisted fraud and monetization into subscription platforms that increasingly resemble legitimate software businesses.


