Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Kali365 PhaaS Expands to Okta and MAX Messenger

Kali365 PhaaS Expands to Okta and MAX Messenger

Posted on June 4, 2026 By CWS

The cybersecurity landscape faces new challenges as the Kali365 phishing-as-a-service (PhaaS) operation broadens its scope. Initially focused on exploiting Microsoft 365, the platform now targets a wider array of services, including Okta and Russia’s MAX Messenger. This expansion poses a significant threat to global cybersecurity efforts.

Growing Reach of Kali365

First identified in April 2026, Kali365 was designed to exploit Microsoft 365 login tokens. By tricking users into authorizing fake device login requests, attackers could gain unauthorized access. Recent developments show that Kali365’s tactics have evolved, now targeting Okta’s single sign-on systems and the Russian messaging platform MAX Messenger, among others.

The platform leverages the OAuth 2.0 device authorization flow, originally intended for devices like smart TVs. Kali365 manipulates this process by embedding legitimate Microsoft login codes into counterfeit document-sharing pages, prompting victims to enter their credentials on Microsoft’s actual site. This cunning approach allows attackers to obtain login tokens without needing passwords or MFA codes.

Arctic Wolf’s Investigation

Cybersecurity firm Arctic Wolf has been tracking Kali365’s operations, documenting its extensive reach. A report shared with Cyber Security News (CSN) highlights a significant expansion of the PhaaS service, which now includes a live command-and-control panel and a phishing cluster of 126 hosts. The campaign’s latest target is MAX Messenger, a state-backed Russian app with over 110 million users.

The FBI had previously alerted the public about Kali365, describing it as a low-barrier tool that democratizes access to sophisticated phishing techniques. At a subscription cost of $250 per month, paid in Bitcoin, the platform is accessible to a wide range of cybercriminals, compounding the threat it poses.

Implications for Cybersecurity

Security experts urge immediate action to counter the Kali365 threat. Arctic Wolf recommends blocking specific domains, such as panel[.]securehubcloud[.]com, and monitoring for suspicious network activity. For organizations using Microsoft 365, disabling the device code authentication flow through Conditional Access policies is advisable.

Additionally, security awareness training remains crucial. Educating users to recognize and report unexpected login prompts can prevent unauthorized access. The propagation model used by Kali365, similar to long-standing Telegram scams, highlights the need for vigilance and robust cybersecurity measures.

As the Kali365 operation continues to evolve, organizations must stay informed and proactive. The potential impact on services like Okta and MAX Messenger underscores the importance of comprehensive cybersecurity strategies to mitigate emerging threats.

Cyber Security News Tags:Arctic Wolf, cyber threats, Cybersecurity, FBI warning, Kali365, MAX Messenger, OAuth 2.0, Okta, PhaaS, Phishing

Post navigation

Previous Post: Willow Secures $7M to Enhance AI System Protection
Next Post: Cisco Addresses Critical Vulnerability in Unified CM

Related Posts

Linux Kernel 6.18-rc1 Released With Extensive Updates Following a Steady Merge Window Linux Kernel 6.18-rc1 Released With Extensive Updates Following a Steady Merge Window Cyber Security News
Threat Actors Compromise 270+ Legitimate Websites With Malicious JavaScript Using JSFireTruck Obfuscation Threat Actors Compromise 270+ Legitimate Websites With Malicious JavaScript Using JSFireTruck Obfuscation Cyber Security News
Weedhack Malware Poses Threat to Minecraft Users Weedhack Malware Poses Threat to Minecraft Users Cyber Security News
AI Uncovers Critical RCE Flaws in Vim and Emacs AI Uncovers Critical RCE Flaws in Vim and Emacs Cyber Security News
AI Exploits Lead to Global FortiGate Cybersecurity Breach AI Exploits Lead to Global FortiGate Cybersecurity Breach Cyber Security News
FortiVoice 0-day Vulnerability Exploited in the Wild to Execute Arbitrary Code FortiVoice 0-day Vulnerability Exploited in the Wild to Execute Arbitrary Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark