logo

From Kali365 to a Wider Device-Code Phishing Ecosystem: A Webamon Intel Pivot Chain

ID: 2195cc19-b411-455b-9a5d-77bda7f6f412

STIX ID: report--2195cc19-b411-455b-9a5d-77bda7f6f412

Threat Score

70/100

Uploaded: 2026-07-24

Created by: dogesec

TLP:CLEAR
...
...
This report documents active Microsoft-themed phishing campaigns—notably device-code phishing and shared-document lures—hosted predominantly on Cloudflare Workers/Vercel infrastructure; it enumerates multiple IOCs (workers.dev subdomains, api.kali365.xyz), groups the activity into families (device-code pages, bot-gated redirectors, direct credential-capture clones, and typosquat domains), and highlights techniques such as multi-stage redirects to login.microsoftonline.com/common/oauth2/deviceauth and client-side bot/sandbox evasion.