Video summary
The Federal Bureau of Investigation has issued a public service announcement warning about an emerging phishing-as-a-service platform known as Cali 365, which first appeared in April and gained significant traction by May. This malicious infrastructure allows cyber threat actors to obtain Microsoft 365 access tokens while bypassing multi-factor authentication without ever needing the victim's actual credentials. The FBI notice highlights how these platforms are primarily distributed via Telegram, enabling hackers to manage campaigns from a centralized back-end panel where they can generate phishing emails, track victims who fall for traps, and steal valuable security keys. Alongside Cali 365, another variant named Octo Pie 365 has emerged around the same timeline, creating a complex ecosystem of duplicate panels that offer extensive functionality including self-service crypto payments and desktop applications designed to streamline cybercrime operations.
The core mechanism behind these attacks relies on a technique called device code phishing, which exploits legitimate Microsoft authentication flows often used for TV sign-ins or remote access scenarios where typing passwords is inconvenient. In this scheme, victims are lured via social engineering tactics—such as fake PDF updates from Adobe Acrobat—to websites that prompt them to copy and paste a generated code into the official Microsoft login page. While the victim's email address, password, and multi-factor authentication codes are sent directly to legitimate Microsoft servers for verification, the hacker intercepts the resulting OAuth tokens in real-time. These stolen tokens act like digital cookies, granting attackers full access to read emails, send messages, and compromise accounts without requiring any further interaction from the user or knowledge of their specific login details.
To maximize damage after gaining initial access, these platforms have evolved into sophisticated cybercrime ecosystems that leverage artificial intelligence to automate post-exploitation activities. The back-end panels allow operators to view captured tokens in a "vault," launch desktop applications built on Electron technology to directly browse victim inboxes, and utilize AI tools like Claude's Sonnet to analyze email threads and draft convincing replies for business email compromise or wire fraud scams. Researchers have analyzed the source code of these unauthorized desktop apps, revealing that they are essentially unsecured web interfaces bundled into executable files using standard installers like NSIS. These applications hardcode old domains while migrating URLs to new variants, demonstrating a clear intent to maintain persistent access and conduct further financial theft once an attacker has established a foothold within the victim's Entra ID environment.
Despite the FBI warning and industry discussions regarding these threats, activity from Cali 365 and its successors continues unabated on underground forums like exploit.in and Telegram channels where threat actors advertise their services. While some chatter suggests operators are closing shop following regulatory pressure, new campaigns persist with little slowdown, indicating that the demand for such tools remains high among desperate cybercriminals. Security firms emphasize that identity-first platforms capable of detecting credential leaks across dark web markets can help lock down compromised accounts before incidents occur at odd hours, but the sheer volume and automation provided by AI make these attacks increasingly difficult to stop manually. The consensus is clear: as long as there are victims willing to click on deceptive links or scan QR codes for device verification, platforms like Cali 365 will continue to pose a severe risk to organizations relying on Microsoft 365 infrastructure.
Read the full video transcript
The FBI put out this notice. The Federal
Bureau of Investigation is issuing this
public service announcement to warn the
public about an emerging
phishing-as-a-service platform called
Cali 365. This PSA is back in May. Cali
365 first appeared in April of 2026. It
has been primarily distributed via
Telegram, enabling cyber threat actors
to obtain Microsoft 365 access tokens
and bypass multi-factor authentication
without intercepting the user's
credentials. Now, in case you're not
familiar with a phishing-as-a-service
platform, I've got one pulled up for you
right here. This is a back-end panel
where a hacker or a cyber criminal would
be able to log in and then actually
manage, generate, create, and send
multiple phishing emails and then keep
track of their organized campaigns as to
what victims they sent them out to, what
victims have fallen for the trap and
they've stolen their access keys for,
and then the hackers have an easy
interface to be able to look through
your emails and do more damage. This is
an active panel online and I don't quite
have credentials. No, thanks, 1Password.
But, in this video we'll take a closer
look what the inside of these panels
look like, some of the tooling and the
code that they use, and some of the
chitchat on Telegram. With the FBI
notice published and the industry seeing
a ton of these Cali 365 campaigns, there
are a lot of people chatting about this.
Here's some info from IBM X-Force and
their threat intel exchange. It's been
in the news. Some of our channel
partners have been covering this, Put
Security, Flare, and even hey, us at
Huntress, right? My day job. We've been
tracking this too. Big shout out to
Tanner, he always sees awesome stuff.
And the Huntress blog carries an
interesting new name in the mix, Octo
Pie 365, alongside Cali 365.
Oh, hey, speaking of the FBI, cool
little episode the other day, hey, when
we got to hang out with the FBI cyber
division assistant director, Bret
Leather. That was a pretty cool
opportunity. I'll leave a link below. I
hope you go tune in. Anyway, I wanted to
introduce the Octo Pi name in your brain
as well, because that is alongside the
Cali 365 conversation. And we had seen
this activity start to blow up just
about the same timeline as the FBI
notice. And throughout all the
communication, you'll see this
discussion of OAuth tokens and how
they're captured with this technique
called device code phishing. I've talked
about device code phishing in a ton of
other videos, but a quick crash course,
you can think of it like you're trying
to log in to Netflix on your television.
You don't have a full keyboard while
you're holding your remote, so you can't
really type in your password. So, the
screen just gives you a string of
letters or numbers in a code that lets
you authenticate. On the screen here,
you can see a little social engineering
lie, a scam, a lure, maybe some email or
some place on the internet drove them to
this website that looks like an Adobe
Acrobat sign in to get some important
update PDF document. But, when they tell
you to copy this code and sign in to
Microsoft, what they do is they open up
a real, actual, legitimate login
authentication method that Microsoft
allows to just use that device code that
they provided and then finish the sign
in. So, the victim's legitimate sign in,
the email address they enter, their
password, even their multi-factor
authentication, goes to legitimate
Microsoft, but because of this device
code fish, the hacker is able to sit in
the middle and see and retrieve those
OAuth tokens. Kind of like the cookie
that lets them log in without needing
any of the info on their real
credentials or MFA. Now, do you remember
that back-end panel that I showed you
just a moment ago? Remember, this portal
is where the hacker could sign in and
generate or create as many of those
lures as they wanted to. Some more of
the research here from Tanner, he says,
"Using Valdin, we were able to find over
150 IP addresses hosting several
variants of that phishing kit panel."
One of the attacks led victims to a a
hosted on Canva, and then that would
lead them to uh the lure of a again
device code that was redacted here, but
another important PDF or shared
document. And then the sign-in with
Microsoft authentication broker. One of
the coolest things with Tanner's
research in this Hunter write-up is how
it's tracking Cali 365 is totally a vibe
coded fishing as a service platform. And
now we're seeing a good many of sort of
these duplicate identical panels with a
different name Octo Pie. But we were
able to dig into them and see, "Look,
there are a ton of different lure
formats, a ton of different
functionality, and self-service crypto
payments, desktop applications for
operators, a whole cybercrime
ecosystem." So look at all these
different lures. I showed you the Adobe
Write PDF review light mode warning.
Sorry, flashbang. You remember this?
This was just one out of like 33 of
these that they have. It's kind of crazy
to see all that it could just crap out
and generate here. And with these
findings, you might have seen in the
text it's all just React pages that we
could pull down, we could recreate that
inside of the back-end panel. What do
the operators get to see? Following
screenshots created here contain fake
data, but they are rendered using the
actual bundles. Here's the inside look
at one of those Octo panels. Octo Pie,
Octo Link, Octo whatever they're calling
it now. So putting our hacker hat on,
right? Bad hacker, cybercriminal threat
actor, we'll play pretend adversary.
This is our lures page, right? We could
see all the created and generated
phishing links, custom landing pages for
SharePoint, OneDrive, Microsoft Teams,
DocuSign. You can see the domain that
they're tied to, the number of visits,
the number of captures that have come
from it. Kind of crazy. Another one is
the token vault for the actual victims
they would have gotten. We can import
tokens manually, but they are the
captured Microsoft 365 accounts. They
let you read inboxes, send emails, and
more. So the inbox button here is pretty
sinister because that will literally,
genuinely take the threat actor into
like a generated clean simple user
interface to just scroll through their
email inboxes, go through all their
email. So it's easy breezy beautiful
CoverGirl to, I don't know, come up with
business email compromise or wire fraud
scams. In fact, they've even powered
that with some AI. So there's literally
a section apparently for Claude's son it
to analyze these email threads and
generate in reply drafts. So they could
hijack a thread and say, "Hey, wire the
money here." That's kind of crafty. You
know, you got to give the devil his due.
Uh hackers are using AI. All right. So
now that we've gotten a look inside the
panel, the couple other things that I
wanted to do in this video was to take a
look at how this is being distributed on
Telegram and take a look at the desktop
applications. There's some really good
insight in the write-up itself. So of
course, I'll leave that linked in the
video description, but I do have the
desktop applications here on my desktop.
I want to check these out after we take
a look at the Telegram side of the
house. At the start of the video, I
mentioned that our channel partner Flare
also dug into Kali 365 and Octo Pi 365
and all the fishing kit things. And we
actually collaborate with Flare quite
frequently, like us and Huntress and
all, right? Uh Evil Tokens when that
campaign was out and about and Kali 365
we were discussing with them just as
well. And they have a really cool
perspective because look, they're seeing
this kind of being shared around. Flare
has the threat intel from the dark web,
like the cybercrime underground. You can
see a listing here on exploit.in,
notoriously known like Russian speaking
cybercrime hacking forum. Someone in a
buying and selling malware threat, they
say, "Hey, contact me if you need Kali
365." Look, in case you're not familiar,
Flare is an identity first cyber threat
intelligence platform that collapses the
gap between an alert and actual
remediation. With their integration
between Entra ID and other identity
providers, the moment that there is any
of your team members, employees,
accounts, and users actually has any of
their information exposed, like their
credentials are in an info-stealer
malware leak site, or information's for
sale on Telegram or the dark web forums,
or even the clearnet or ransomware leak
sites, then you could have that account
locked down, actually session
quarantined, and remediated and resolved
before an incident occurs at like 2:00
a.m. on a Saturday. If you've seen any
of my videos before, you know that I am
a huge Flare fanboy, and they have
always supported the channel, and they
are the sponsor of today's video. So,
please do give them some love, link
below in the video description. But, you
know me, I like a little bit of a
tactical topic, so we'll use Flare to
actually continue some of the research
and go find more about Cali 365. Let me
collapse here, and a lot of these are
probably just going to be some news
syndication. Oh, someone posted on
Dread. One of the coolest things about
Flare is they give us a raw link to go
see it at the source. Oh my goodness,
this is a post from a week ago. Did
anyone try Cali 365 yet? I've been
getting better at fishing the last
couple months. I've been doing some
business email compromise attacks, too,
with my own fishing page to companies of
my country. I'm sorry, Rome 00, but I
don't think this is it. Worker Bee
responds, I'm genuinely surprised any
type of fishing still works in 2026.
It's really true, people are dumb.
All right, [clears throat] I feel like
it's a little bit of victim blaming,
Worker Bee. Oh, this is the exploit.in
one they showcased. This was the
screenshot they had on their blog. Can I
go visit that? Oh, well, I can't really
read that language, but well, it's what
you'd expect, you know. A lot of folks
distributing it, though, you can see
Cali 365 available. Some folks saying,
"Hey, I got it set up." Someone says, "I
need that Cali 365. Who has Cali 365?"
BJ 17681, anyone with an update on Cali
365 who knows about that Wow, guys are a
little desperate. All right, I'm going
back a bit, and I found a Cali 365 user
sending Telegram messages inside of a
Telegram channel called Cali 365. So,
I'm curious about that one and I'm
loading the page here. Cali 365
with a description of World Cup 2026.
So, I click view in Telegram.
Uh
and I think they either scrub the
channel or
I don't know. Let's join it. Yeah, no,
there's there's nothing in there. So,
let's just take a little peek at our
OctoLink Sender and OctoLink Live. I
want to try to look at Sender first. I'm
double-clicking on that. Look at it. The
description here, OctoLink B2B email
sender desktop app. If I take a look at
the properties, it is not signed, but it
does have filled in details here for
everything pertinent to it. And oh,
okay, it looks like it's starting up in
the background here. Oh, I do not have a
login. Nor do I actually want to log in
cuz I don't do that. How about OctoLink
Live 3? They're probably both going to
ask me for authentication. Yeah, I don't
have that.
Oh, but you can see the electron logo on
the icon at the very top here. These are
electron applications, it seems. So,
with that, I'm going to hop over to a
REMnux virtual machine. I do have the
files staged here and I'm going to open
that up with my terminal. Put them
inside of a directory for us to work
with here. You can see that both of
these do state that they are using the
Nullsoft installer. I think that's NSIS.
So, if we're to consider both of these
files as kind of their own archives and
treat them actually using this 7-Zip
utility, we could use like the list sub
command or just L on any of these. Let's
get OctoLink Live and you'll be able to
see some of the pertinent DLLs here. Of
course, NSIS for the installer and
app-64,
all part of this plugins directory that
is usual boilerplate for that NSIS tech.
So, we could go ahead and extract with
the X command there on that OctoLink.
Now, you'll be able to see that created
that plugins directory and I'm going to
have to escape out that dollar sign so
my command line doesn't think that it is
a variable. And let's then go ahead and
extract the app64.
That will break out everything,
including the resources and everything
that might have been bundled with that
application here. And you'll see things
pertinent to running this like inside of
Chromium because okay, Electron is
having a little bit more of that web
native capability. But what we're
interested in is the resources folder
here for Electron apps. That app.asar is
something that we'd love to be able to
look at. We can install the Electron
ASAR utility. And does that have a list
command? Yeah, okay. I think we can give
it that app.asar, and that will dump all
of the things that are pertinent in
here. So if we were still for whatever
reason squeamish or uncertain about the
connection between OctoPrint, OctoPrint,
and Cali 365, I guess the original 1.0
executable is whatever part of the
resources folder there. And it includes
all of the node modules that are
included in the original source code
here. So it's neat to be able to list
all these out, but ultimately we want to
extract them and see the pertinent
source code. Gosh, the node modules
folder is just absolutely
uh bloated. Let's extract app.asar. Oh,
and it needs a destination. Let's just
put it like uh output directory, and now
it will live in that output directory
for us. Can I open that up with Sublime
Text? Do I have that in my uh arguments?
I do. It's in my path at least. Okay, so
we have the icon. Looks a lot better
here than it did on Windows in the
desktop. package.json
pretty clear. Tells us the main script
or JavaScript code that this runs out of
is that index.js. And it looks like
there are some I think probably
boilerplate Electron things that happen
at the very start here. But then we are
retrieving some of the modules and then
building out the capability for having
that front end. Uh the menu options that
we would have seen in the very top bar.
We could scroll through index.js, but
there's not going to be a whole lot of
here other than okay, it's presenting
the interface to us. IPC looks like a
lot of the communication back and forth
with how you interact with the panel.
You can see the entries to like log in,
log in with two factor, get me refresh
token, et cetera. The panel API is
probably where a lot of the more
interesting things tend to happen. And
that way again, we can probably see some
of the potential endpoints that the
panel might be exposing or revalidate
findings that we could have seen from
Valdin or Shodan. Other things that
would be part of the research process,
right? Preload.js, prt off.js. Ooh,
primary refresh token authentication in
pure node. That's
neat and looks pretty AI, right?
>> [laughter]
>> HTTP helpers though, and then all of the
like genuine implementation to be able
to do well, okay, device registration,
granted all of the authentication
capabilities. So it's like device code
fish in JavaScript. That is
kind of cool, if I may say. Look, we
know this is all vibe coded. So like you
can have whatever opinion that you would
like there, but it's crazy to see the
extent of streamlined tooling. You know
what I mean? Service window.js.
Oh, is this to like give them the quick
conveniences of like exploring their
inbox for one thing? Presumably, here's
a launch Outlook capability. So yeah, it
would just open it up in their browser
capability so that it's extremely easy
for the operator. You barely have any
extra clicks or understanding. You're
just immediately in their inbox. That
must be the interface that we were able
to see in a lot of the things that this
allows it to do. Just in an easy
side-by-side a desktop application. Do
we need to even look at the sender,
honestly? I think you're probably going
to see the similar understanding of node
electron application. Package.json for
the email sender once again pretty
outright. This carries a dist electron
with it. Whoa. Main.js and others look
like there is intended to be a lot more
convenience for hey yeah, being able to
just mass spam out emails and they've
got the database schema put together
here though. That's kind of interesting
to be able to look at. Oh yeah, you can
see their old domains that they just
have hard coded in here. Wow.
Migrate stored panel URLs from old
domains now to OctoPi.
>> [laughter]
>> Sorry, I just think it's interesting to
see some of like the potential
breadcrumbs. Like obviously they're
using the default client ID. I presume
that's for the Microsoft authentication
broker one that they send the device
code fish from and you could see like
the database paths they would have on
their system. Like piecing this all
together here, all this intelligence is
just kind of interesting. There are some
more details on the desktop applications
again in the Hunters write up that I'll
have linked down below if you're
interested. Again, really just wild to
see okay, utilizing a browser like this
means it's kind of going to be coming
from a normal legitimate web browser
using the SSO cookies as if that's the
real end user. That's the real end goal
here, right? Is to take advantage of
that full end user, that person, that
identity, any end user and then even
operate with emails that will be sent
after the fact for business email
compromise, for wire fraud, for further
post exploitation and damage that can be
done once they have a foothold inside
your Entra ID environment. Some
detection rules here for you and again
uh FBI's been chatting about this
because it was just such a big big
campaign. But that's not to say the
campaign is really over, right? Uh we
saw the Telegram chat messages when the
threat actors had noticed after the FBI
PSA was released, hey we're shutting our
doors, we're closing up shop, we're
ceasing operations. But we're still
seeing activity and it's not easy to
say, okay, you know what, Cali365,
OctoPi365,
Freedom365, whatever the fishing kit du
jour is, it's not particularly slowing
down. We can see that AI is really
enabling all of that, and they're going
after you
and your teammates, and your employees,
and your colleagues, and your peers, and
you and your identity. So, really love
Flare and the great work that they've
been doing. Again, super duper thankful
for them sponsoring this video and
always offering their support. And it's
always super cool to be able to
collaborate on cases like these. So,
please do give them some love. Link
below in the video description. Huge
shout out to Flare. Thanks so much for
your support. Thank you for watching
this video. I hope you had a little bit
of fun and hey, cracking open the code,
taking a look at what these panels look
like, what the desktop applications look
like, and seeing a little bit more
behind the scenes. Thanks so much. I'll
see you in the next video.