SevinHub / OSINT Portfolio / Case 016
Previous: Case 015 — Klarna Refund PhaaS All Cases
P1 Critical PhaaS Platform OAuth Token Hijack MFA Bypass FBI PSA I-052126 Domain Seizure

Kali365 — Microsoft 365 OAuth Device Code PhaaS
FBI PSA · Dual Domain Seizure · 90 Tencent Cloud IPs · Telegram Bot Leak

FBI-flagged Phishing-as-a-Service platform distributing Microsoft 365 OAuth token hijacking kits via Telegram since February 2026. The kit abuses device code authentication flow and AiTM reverse proxy to capture OAuth refresh tokens and session cookies without intercepting user passwords or MFA codes — granting persistent access to Outlook, Teams, OneDrive, and SharePoint admin portals. Approximately 500 affiliates, $200K–$350K subscription revenue, fake FBI-day closure, then continued operations under "Green Octopus" rebrand.

Kali365 / Green Octopus PhaaS Microsoft 365 OAuth Device Code AiTM MFA Bypass kali365.xyz serverHold securehubcloud.com clientHold AS132203 Tencent BL Networks Wyoming Telegram Exfil 500 Affiliates OxaPay Crypto T1528 · T1111 · T1566
Entry Domain
kali365.xyz
Status
serverHold (Seized)
First Seen
2026-04-18
Registrar
NameSilo, LLC
Affiliates
~500 by May 2026
Revenue (Est.)
$200K–$350K
Campaign IPs
90+ (AS132203)
Target
Microsoft 365
Finding 1 PhaaS Platform Architecture — Kali365 / Green Octopus 3.1.0 Subscription Kill Chain

Kali365 operates as a tiered subscription PhaaS platform distributed via Telegram since February 2026, first catalogued by Palo Alto Unit42 on 2026-04-24. At $250/month paid in Bitcoin or USDT (via OxaPay gateway), the platform attracted approximately 300 affiliates by end of March 2026 and 500+ by May 2026 before the FBI PSA triggered a theatrical shutdown. Revenue is estimated at $200K–$350K across the full February–June 2026 operation window.

The platform ships in three editions. E1 provides the base AiTM and device code kit with 33 lure templates targeting Microsoft 365 services (Teams, Outlook, SharePoint, OneDrive), DocuSign, Dropbox, Google Drive, and Adobe. E2 adds a post-compromise AI-BEC module with Exchange admin abuse, keyword monitoring for payment/invoice-related emails, and a contact harvester that extracts victim organization communications for downstream fraud. E3 is a reseller edition with self-service provisioning, enabling a multi-tier affiliate model where sub-affiliates purchase access via shared referral links.

The desktop component, branded "OctoLink Live" (also seen as "kali365-live" and later "Green Octopus 3.1.0"), is an Electron application that loads captured OAuth tokens and provides authenticated one-click access to victim Outlook, OneDrive, and SharePoint portals without requiring any password or MFA interaction. A companion tool, "OctoLink Sender," uses the Microsoft Graph API to send lateral phishing from compromised mailboxes at 2,500 emails per token per day, with burst limiting (80 sends with 120-second cooldowns) and human-like jitter (5–12 second pauses every 12–19 sends) to evade mail flow anomaly detection.

"Ghost mode" automatically removes MFA notifications, password change alerts, and sign-in warning emails from victim inboxes, suppressing victim awareness of the compromise. The full device code authorization flow from lure delivery to token capture completes in approximately 42 seconds.

# Kali365 Platform Editions and Capabilities Edition Capabilities ───────────────────────────────────────────────────────── E1 Base AiTM + Device Code, 33 lure templates, token vault E2 BEC AI-BEC analysis, Exchange admin, keyword alerting E3 Reseller Self-service provisioning, sub-affiliate management # Subscription Economics Price $250 USD / 30 days Currencies BTC, USDT (Tron network) via OxaPay Affiliates ~300 March 2026 → ~500+ May 2026 Revenue est. $200,000 – $350,000 (Feb–Jun 2026) Wallet moved ~$128K USDT off-chain via centralized exchanges # Desktop Tool Signatures App name OctoLink Live / Green Octopus 3.1.0 User-Agent kali365-live/1.0.0 MS Client ID d3590ed6-52b3-4102-aeff-aad2292ab01c (Office app) Session model persist:svc-{tokenId}-{service} (Electron partition) # OctoLink Sender Rate Limits (evasion tuned) Daily cap 2,500 emails per stolen token Burst pattern 80 sends → 120s cooldown Jitter 5–12s pause every 12–19 sends (human simulation)
Ghost mode actively suppresses MFA alerts, password change emails, and sign-in notifications from victim inboxes. Victims have no visibility of the compromise. OAuth refresh tokens provide access for months without requiring re-authentication.
Finding 2 Domain Infrastructure — Dual NameSilo Seizures Confirmed

WHOIS inspection reveals that both primary Kali365 infrastructure domains have been placed on hold by NameSilo, LLC. The original platform domain kali365.xyz carries serverHold status, indicating a registry-level seizure — typically issued under law enforcement coordination or ICANN abuse action. The panel domain securehubcloud.com, the migration infrastructure registered on May 16, 2026 (three days before the FBI PSA), carries clientHold status, indicating a registrar-initiated hold by NameSilo following the FBI publication.

The branding timeline shows rapid iteration: kali365.xyz → octopi365.com → blackoctopusking.live (announced May 7, 2026) → securehubcloud.com (registered May 16, 2026). The operators notified customers on May 21, 2026 — the same day the FBI PSA published — that they were "officially closing the website and discontinuing operations." Intelligence from SpyCloud and Huntress confirms activity continued post-announcement under the "Green Octopus" brand.

SSL certificate transparency for securehubcloud.com shows 7 confirmed subdomains provisioned via Let's Encrypt (E8/E7 chains) and Sectigo within a 3-day window. The origin.securehubcloud.com subdomain resolved directly to the BL Networks panel IP 66.179.30.87 before Cloudflare proxying was applied, exposing the backend hosting provider. The privacy-protected WHOIS registrant (PrivacyGuardian.org, Phoenix AZ) is consistent with all previous Kali365 domain registrations.

# WHOIS — kali365.xyz Creation Date 2026-04-18T17:32:26Z Registrar NameSilo, LLC Name Servers NAYA.NS.CLOUDFLARE.COM / DAKOTA.NS.CLOUDFLARE.COM Status serverHold ← REGISTRY SEIZURE Status clientTransferProhibited Live Check HTTP:000 TIMEOUT/DEAD # WHOIS — securehubcloud.com (migration panel) Creation Date 2026-05-16T19:02:44Z Registrar NameSilo, LLC Registrant PrivacyGuardian.org / 1928 E. Highland Ave. Phoenix AZ Name Servers JULIAN.NS.CLOUDFLARE.COM / LUCY.NS.CLOUDFLARE.COM Status clientHold ← NAMESILO REGISTRAR ACTION Updated 2026-05-21T21:40:13Z (same day as FBI PSA) # crt.sh — securehubcloud.com SSL Certificate Timeline Cert 1 issued 2026-05-16 (Let's Encrypt E8) Cert 2 issued 2026-05-19 (Let's Encrypt E7) Cert 3 issued 2026-05-19 (Sectigo DV E36) Subdomains origin / boss / api / panel / www / *.securehubcloud.com Backend IP 66.179.30.87 (BL Networks, Sheridan WY — via origin subdomain) # Branding Timeline 2026-02-15 First branded "Kali365" capture observed 2026-04-18 kali365.xyz registered (NameSilo) 2026-05-07 Migration announced → blackoctopusking.live 2026-05-14 Source code updated: "Green Octopus 3.1.0" 2026-05-16 securehubcloud.com registered (new panel) 2026-05-21 "Official closure" — posted FBI PSA then announced shutdown Activity confirmed CONTINUED post-announcement # All Domain Status kali365.xyz serverHold — DEAD securehubcloud.com clientHold — DEAD blackoctopusking.live No DNS record — DEAD octopi365.com No response — DEAD
Both kali365.xyz (serverHold) and securehubcloud.com (clientHold) are confirmed seized at NameSilo as of the investigation date. The fake "closure" announcement synchronized with the FBI PSA did not end operations — the platform continued under Green Octopus branding until infrastructure was seized.
Finding 3 Campaign Infrastructure — 90 Tencent Cloud Operator IPs (AS132203) + BL Networks Panel

Huntress published 90 confirmed Tencent Cloud IPs used by Kali365 affiliates to conduct device code authentication attempts against victim Microsoft 365 accounts. All 90 IPs fall within AS132203 (TENCENT-NET-AP-CN, Tencent Building, Kejizhongyi Avenue, Shenzhen, CN), predominantly in the CIDR range 43.173.64.0/18 with additional clusters in 43.130.x.x, 43.131.x.x, 43.135.x.x, 43.153.x.x, 43.157.x.x, 43.159.x.x, 43.165.x.x, 43.166.x.x, 49.51.x.x, 162.62.x.x, and 170.106.x.x. These IPs appear in Microsoft Unified Audit Log (UAL) entries as the sources of successful device code authentication grants.

The operator control panel ran on 66.179.30.87 (BL Networks LLC, Sheridan, Wyoming, abuse: admin@blnwx.com) before Cloudflare proxying. This IP is now dead. A secondary BL Networks IP, 199.91.220.111 (CIDR 199.91.220.0/23, NetName BNL-77), returns nginx/1.24.0 Ubuntu on all paths with HTTP 404 — server alive, panel content stripped. This is consistent with panel migration or takedown response.

The 126-host cluster documented by Arctic Wolf (active May 6–27, 2026) was deployed as a single backend rotated across disposable front-end domains, enabling rapid campaign regeneration after domain seizures. Cloudflare Workers and Pages.dev instances handled lure routing, with discovered worker patterns matching [a-z]{5}-[a-z]{4}-[a-z0-9]{4} naming conventions across multiple Cloudflare accounts.

# Tencent Cloud Campaign IPs — AS132203 (90 confirmed) ASN AS132203 TENCENT-NET-AP-CN Primary CIDR 43.173.64.0/18 (~16,384 IPs, heavily abused) Additional 43.130.x.x, 43.131.x.x, 43.135.x.x, 43.153.x.x 43.157.x.x, 43.159.x.x, 43.165.x.x, 43.166.x.x 49.51.x.x, 162.62.x.x, 170.106.x.x Sample IPs 43.131.0.54, 43.153.2.249, 43.157.64.101, 170.106.119.249 # Panel Hosting — BL Networks Wyoming (admin@blnwx.com) Panel IP 66.179.30.87 — DEAD (post-seizure) Secondary IP 199.91.220.111 — nginx/1.24.0 Ubuntu HTTP:404 CIDR 199.91.220.0/23 (BNL-77, BL Networks) Abuse admin@blnwx.com / +1-307-317-1097 Open ports 22 (OpenSSH 9.9p1) · 80 · 443 · 8443 (operator panel) # Panel API Endpoint Mapping (from Huntress + Unit42) /dash/auth Operator login /dash/tokens Stolen OAuth token vault /dash/lures AI lure template manager /dash/send-jobs/{id} Live campaign sender /dash/bec/analyze AI-BEC invoice/payment filter /dash/highvalue High-value target triage /dash/my-worker Cloudflare Worker management /dash/exchange Exchange admin abuse module /admin/users Affiliate management /admin/billing Subscription billing # SIEM Detection Indicators UAL anomaly Tencent AS132203 IP in device code auth grant UAL anomaly Refresh token grant WITHOUT interactive sign-in UAL anomaly Python-requests UA from operator ASN UAL anomaly Electron UA in Microsoft sign-in logs Mail anomaly Non-existent message GET (404s post-send pattern)
The 90 Tencent Cloud IPs are the detection anchor. Any Microsoft 365 sign-in log showing a device code authorization grant from AS132203 (43.130-43.173.x.x range) should be treated as a confirmed Kali365 compromise. Refresh token grants with no preceding interactive sign-in are the second key indicator.
Finding 4 Telegram Bot Token Leak — @NovosibyrskyMoneyBot Credential Exfiltration Channel Exposed

Arctic Wolf researchers, during active investigation of the Kali365 operator expansion into MAX Messenger (Russian state-backed messaging platform), documented the Telegram exfiltration bot credential in full. The bot @NovosibyrskyMoneyBot (internal name: sova_novosibirsk_bot) receives stolen phone numbers, one-time passwords, and 2FA passwords captured from victims across all supported phishing templates.

The bot name is a direct Russian language reference: "Novosibirsk" is the third-largest city in Russia (Siberia), and "Novosibirsky Money" maps to a known Russian-language underground financial fraud context. The "sova" prefix (Russian for "owl") is a recurring theme in Russian-speaking cybercrime infrastructure. This operator naming convention strongly suggests a Russian-speaking threat actor group operating out of or affiliated with Siberia-based criminal networks.

The leaked token format 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg follows the standard Telegram Bot API format (bot_id:secret). The numeric prefix 8535071077 is the bot user ID. The chat group -5035652280 (negative ID indicating a group or supergroup, not a direct chat) is the delivery channel for all exfiltrated credentials.

The MAX Messenger phishing flow the bot supports captures Russian phone numbers (+7 prefix), legitimate MAX SMS/push OTPs, and 2FA passwords in sequence — a complete account takeover chain for Russian consumers alongside the primary M365 targeting.

# Kali365 Telegram Exfiltration Channel (via Arctic Wolf) Bot Username @NovosibyrskyMoneyBot Internal name sova_novosibirsk_bot Bot Token 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg Bot ID 8535071077 Chat Group ID -5035652280 (supergroup — credential delivery channel) Exfil data Phone numbers, OTPs, 2FA passwords, account recovery codes # Operator Origin Intelligence Bot name ref Novosibirsk = 3rd-largest Russian city (Siberia) Prefix "sova" Russian for "owl" — recurring RU-speaking cybercrime tag Language Russian-speaking threat actor group (assessed) # Tracking Pixel Infrastructure (still LIVE as of investigation) Pixel domain tk.mowell.tech — HTTP:405 ACTIVE Tracking ID 906596682876295936 CNAME chain tk.mowell.tech → https-api.bytegle.tech Bytegle ASN Alibaba Cloud (AWS Route53 NS) — China-routed Pixel IPs 141.11.124.140 / 162.141.119.128 / 143.20.90.69 mowell.tech reg 2023-07-28, Alibaba Cloud HiChina (updated 2025-06-17) # Crypto Payment Wallet Intelligence Gateway OxaPay (crypto payment processor) Primary assets BTC, USDT (Tron TRC-20 network) Cashout ~$128K USDT consolidated and moved off-chain Routing Traced to flagged illicit-finance wallet cluster
The Telegram bot token is live intelligence — it has been reported to Telegram's abuse channel and to EC3/Europol. The token was documented by Arctic Wolf and is referenced here from their published report. Reporting this to Telegram Law Enforcement enables chat log extraction under legal process. The chat group ID (-5035652280) contains captured credential flows from all Kali365 affiliate campaigns.
Finding 5 Multi-Platform Expansion — MAX Messenger, Okta, AWS, Xerox, GMX, LiveDrive Beyond M365

Arctic Wolf documented a significant expansion of the Kali365 operator's targeting scope beyond Microsoft 365, establishing this as a multi-platform identity theft operation. The operator deployed phishing pages targeting MAX Messenger (Russian state-backed messaging platform), Okta SSO, Xerox DocuShare, GMX (German email), LiveDrive (UK cloud storage), Mail.ru, Yandex Disk, Odnoklassniki, and AWS (mimicked endpoint naming). The Russian-platform targeting (MAX, Mail.ru, Yandex, Odnoklassniki) alongside Siberia-branded Telegram infrastructure corroborates the Russian-speaking operator hypothesis.

The MAX Messenger phishing domain greatness-marketing[.]top deployed a prize-claim social engineering lure. The backend attachedfile[.]com (39 subdomains observed, registered 2026-02-14 by Hostinger, last updated 2026-07-21) served as a persistent Cloudflare-proxied front for lure hosting across multiple campaigns. The domain predates Kali365's April public launch by two months, suggesting earlier-stage infrastructure preparation or a shared prior operation.

Detection fingerprints identified across all expanded deployments: HTML loader text "Preparing your secure document..." shared across all lure templates, and Cloudflare Workers with same-origin fetch pattern data-form-o5pu[.]p-ntz8agp6[.]workers[.]dev. The VALIDIN banner hash febb622cd9eeb5c8860dcef4cbfd4b74 and TLS certificate SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a provide consistent infrastructure fingerprinting across all Kali365/Green Octopus deployments.

ANY.RUN analysis identified 34 phishing domains in the Kali365 campaign infrastructure, predominantly using .de TLD — strongly clustering on German-sounding generic names as lure delivery domains, with a secondary cluster on workers.dev Cloudflare-hosted templates.

Live verification (2026-08-19): Navigating directly to tk.mowell.tech in a browser returns {"msg":"invalid uri"} — a structured JSON error from custom application code, not a generic web server response. This is definitive proof the tracking backend is still running live business logic. The server is not a parked page or residual nginx default — it is an active API endpoint waiting for victim tracking tokens appended to specific URI paths. The operators shut down the phishing front-ends but left their data collection engine completely running. Three months after the FBI PSA "closure," the tracking infrastructure is still operational.

# Multi-Platform Targets Beyond Microsoft 365 MAX Messenger Russian state-backed messenger (phone OTP capture flow) Okta SSO Enterprise SSO identity provider Xerox DocuShare Document management (enterprise supply chain vector) GMX German email provider LiveDrive UK cloud storage Mail.ru Russian email/cloud Yandex Disk Russian cloud storage Odnoklassniki Russian social network (VKontakte equivalent) AWS Mimicked AWS endpoint naming # Infrastructure Fingerprints (cross-campaign) HTML loader "Preparing your secure document…" Worker pattern data-form-o5pu[.]p-ntz8agp6[.]workers[.]dev Banner hash febb622cd9eeb5c8860dcef4cbfd4b74 (VALIDIN) TLS SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a API endpoints /api/generate?lure=ID / /api/status/N / /api/lure-config/ID # .de Domain Infrastructure (34 confirmed, ANY.RUN) flexiscalesystems.de guardedwebsolutions.de reputationboosters.de prowebsitemakers.de onlinebrandinghub.de modernwebbalance.de marketadaptabletech.de brandswithintegrity.de turnideastoresults.de reliablebusinesstech.de performancereputation.de trustinbrands.de [+23 more] # Cloudflare Worker / Pages Domains tryingdocusign.pages.dev HTTP:000 (suspended) sharepoint-81c.pages.dev HTTP:403 (CF block) sharepoint-63m.pages.dev HTTP:403 (CF block) cloud-microsoft-drive-for-business.workers.dev (discovered) # Attachment / Lure Delivery Infrastructure attachedfile.com HTTP:404 (CF alive, registered 2026-02-14, Hostinger) greatness-marketing.top MAX Messenger prize lure (CF, dead) # LIVE VERIFICATION — tk.mowell.tech (browser GET, 2026-08-19) Request GET https://tk.mowell.tech/ (browser, Belgian IP) Response {"msg":"invalid uri"} Meaning Custom JSON API running — expects victim token in URI path e.g. /track/{victim_id} or /pixel/{token} Not nginx default This is active application code — Node.js or Python backend Conclusion Tracking data collection engine still LIVE 3 months post-"closure" FBI + Huntress + Arctic Wolf missed this — infrastructure incomplete takedown
The .de domain cluster (generic German-sounding business names) is a deliberate anti-detection strategy. Registrars and threat intel feeds are less likely to flag "modernwebbalance.de" or "trustinbrands.de" as malicious without active investigation. These domains serve as lure delivery points that redirect to the actual phishing template hosted on Cloudflare Workers.
Finding 6 Device Code Phishing Kill Chain — 42-Second Token Capture to Persistent Access

The Kali365 attack chain exploits the OAuth 2.0 Device Authorization Grant (RFC 8628), a flow designed for input-constrained devices like smart TVs, printers, and IoT hardware. The attacker initiates the flow against their own registered application (Microsoft client ID d3590ed6-52b3-4102-aeff-aad2292ab01c, the Office app identity), obtains a user_code valid for 15 minutes, and embeds it in a phishing lure. When the victim visits microsoft.com/devicelogin (a legitimate Microsoft URL) and enters the code, the attacker's application receives the OAuth access_token and refresh_token directly from Microsoft's authorization server.

No phishing proxy is needed. No fake login page. The victim interacts only with real Microsoft infrastructure. MFA completes legitimately. The attacker's session is authorized before the victim closes the browser. The refresh token provides access for months without re-authentication, enabling persistent Outlook, Teams, OneDrive, and SharePoint access.

The E2 post-compromise module then weaponizes the compromised mailbox: a contact harvester extracts all communications, a BEC keyword engine flags emails matching payment, invoice, wire transfer, and accounting terms, and the AI template generator crafts reply-chain phishing messages using the victim's real email history and writing style. The "Ghost mode" suppresses all Microsoft security notifications from the victim's inbox, maintaining stealth for the full access window.

The parallel AiTM path (Evilginx2 reverse-proxy "ginX" instances) captures ESTSAUTH session cookies and OAuth artifacts from interactive MFA sessions, providing an alternative capture method for targets that do not follow the device code lure.

# Kali365 Device Code Kill Chain (RFC 8628 abuse) Step 1 Attacker initiates device code flow against MS App ID: POST https://login.microsoftonline.com/common/oauth2/v2.0/devicecode client_id=d3590ed6-52b3-4102-aeff-aad2292ab01c Step 2 Microsoft returns: user_code (8-char alphanum), device_code, verification_uri verification_uri = https://microsoft.com/devicelogin (LEGITIMATE URL) Step 3 Phishing lure delivered via Canva-hosted page / .de lure domain "Sign in to share document — visit microsoft.com/devicelogin, enter: [code]" Step 4 Victim navigates to real Microsoft page, enters attacker's user_code Victim completes legitimate MFA — interacting only with Microsoft servers Step 5 Attacker polls /oauth2/v2.0/token — receives access_token + refresh_token Compromise complete in ~42 seconds from code entry Step 6 OctoLink Live app loads token — one-click access to Outlook / SharePoint Step 7 Ghost mode: MFA alerts, password change emails, sign-in warnings deleted Step 8 E2 BEC module: contact harvest → keyword filter → reply-chain phishing # AiTM Parallel Path (ginX reverse proxy) Method Evilginx2 instance proxies Microsoft login Capture ESTSAUTH cookie + OAuth artifacts from interactive MFA session Result Same persistent access, no device code required # MITRE ATT&CK Mapping T1566.002 Phishing — Spearphishing Link (initial lure delivery) T1528 Steal Application Access Token (core technique) T1111 Multi-Factor Authentication Interception (device code bypass) T1539 Steal Web Session Cookie (AiTM path, ESTSAUTH) T1567.002 Exfiltration Over Web Service — Telegram T1583.001 Acquire Infrastructure — Domains (NameSilo, Cloudflare) T1036 Masquerading (Office app client ID, Canva-hosted lures) T1078.004 Valid Accounts — Cloud Accounts (persistent OAuth session) T1564.008 Hide Artifacts — Email Hiding Rules (Ghost mode)
This attack technique requires no password. It requires no credential phishing. It bypasses MFA completely. The victim interacts only with legitimate Microsoft infrastructure. The only defense is restricting device code flow via Conditional Access Policy or blocking Microsoft OAuth app ID d3590ed6-52b3-4102-aeff-aad2292ab01c from authorization in organizational tenants.
Reporting
FBI / IC3 (existing PSA)
www.ic3.gov/complaint (PSA: I-052126-PSA)
Primary investigators. PSA published 2026-05-21. Any new infrastructure or affiliate activity supplements existing FBI case file.
CISA (Cybersecurity and Infrastructure Security Agency)
report@cisa.gov
US critical infrastructure targeting: construction, manufacturing, healthcare, government sectors explicitly documented as primary victims.
EC3 / Europol (EU cross-border PhaaS)
ec3@europol.europa.eu
EU victim clusters in Australia, India, Canada, Germany (GMX targeting). Multi-jurisdiction coordination needed.
CCB / SafeOnWeb Belgium
suspicious@safeonweb.be
Belgian awareness. GMX targeting and EU sector victims include Belgian enterprises. BEC module weaponizes compromised Belgian mailboxes for downstream attacks.
NameSilo (Registrar — both domains seized)
abuse@namesilo.com
Both kali365.xyz and securehubcloud.com are already on hold. Reporting confirms awareness and requests permanent suspension and domain transfer block.
BL Networks (Panel hosting provider)
admin@blnwx.com
199.91.220.111 (nginx alive, HTTP 404) remains under BL Networks control. Requesting full nullroute and account termination.
Telegram Law Enforcement / Abuse
abuse@telegram.org
Exfiltration bot @NovosibyrskyMoneyBot (bot ID 8535071077) with documented credential delivery channel. Token: 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg
Investigation Method
Phase 1 — Target Discovery: FBI/IC3 Public Service Announcement I-052126-PSA (2026-05-21) flagged Kali365 as an active PhaaS distributing Microsoft 365 OAuth token hijacking kits via Telegram. Investigation initiated 2026-08-19 following a YouTube video by John Hammond covering the FBI PSA.
Phase 2 — Technical Intelligence Gathering: Cross-referenced FBI PSA with published research from Huntress (device code ecosystem deep-dive), SpyCloud (anatomy + branding timeline), Arctic Wolf (multi-platform expansion), Palo Alto Unit42 (April 2026 first report), ANY.RUN (malware trends + domain list), Todyl (infrastructure enumeration), and Doppel (PhaaS overview). Pulled Huntress GitHub IOC CSV (283 lines, 90 IPs).
Phase 3 — Live Infrastructure Verification: HTTP HEAD checks on all known domains. kali365.xyz: HTTP:000 DEAD. securehubcloud.com: HTTP:000 DEAD. blackoctopusking.live: No DNS record. 199.91.220.111: nginx/1.24.0 Ubuntu, HTTP:404 (server alive). tk.mowell.tech: HTTP:405 ACTIVE (tracking pixel). sharepoint-81c/63m.pages.dev: HTTP:403 (Cloudflare blocked). attachedfile.com: HTTP:404 (Cloudflare).
Phase 4 — WHOIS and Certificate Transparency: WHOIS confirmed kali365.xyz serverHold (registry seizure) and securehubcloud.com clientHold (NameSilo registrar action, updated 2026-05-21 = FBI PSA day). crt.sh enumeration of securehubcloud.com revealed 7 subdomains and backend IP 66.179.30.87 (BL Networks Wyoming) via origin subdomain before Cloudflare proxying was applied.
Phase 5 — ASN and Reverse IP Analysis: Confirmed AS132203 (Tencent Cloud) as primary campaign IP block hosting 90 operator IPs. BL Networks secondary IP 199.91.220.111 confirmed alive via direct HTTP check (nginx/1.24.0, all paths 404 — panel stripped).
Phase 6 — IOC Consolidation and MITRE Mapping: Extracted all IOCs from public intelligence sources. Mapped 8 MITRE ATT&CK techniques. Documented tracking pixel (tk.mowell.tech) as live remaining infrastructure. Compiled reporting package for FBI/IC3, EC3/Europol, CCB, NameSilo, BL Networks, and Telegram abuse.
IOC Table
Type Indicator Status Notes
Domainkali365.xyzSEIZED (serverHold)Primary platform domain — NameSilo registry action
Domainsecurehubcloud.comSEIZED (clientHold)Migration panel domain — NameSilo registrar action 2026-05-21
Domainblackoctopusking.liveDEADRebranding migration domain (announced 2026-05-07)
Domainoctopi365.comDEADEarlier brand variant
Domainattachedfile.comCF 404Lure hosting — registered 2026-02-14, Hostinger, 39 subdomains
Domaingreatness-marketing.topDEADMAX Messenger prize phish lure
Domaintk.mowell.techACTIVE (HTTP 405)Tracking pixel — CNAME bytegle.tech (Alibaba Cloud)
Domainbluefoodtruths.xyzUnknown.de lure cluster (ANY.RUN — 34 domains identified)
Domainflexiscalesystems.de + 33 .de domainsUnknownLure delivery domains — generic German branding
Domainsharepoint-81c.pages.devHTTP 403 (CF blocked)Cloudflare Pages phishing template
Domainsharepoint-63m.pages.devHTTP 403 (CF blocked)Cloudflare Pages phishing template
IP66.179.30.87DEADPanel server — BL Networks Wyoming (admin@blnwx.com)
IP199.91.220.111nginx alive (404)BL Networks Wyoming — panel stripped, server alive
IP141.11.124.140ACTIVETracking pixel IP (bytegle.tech)
IP range43.173.64.0/18AS132203 TencentPrimary campaign operator IP CIDR (90 IPs confirmed)
IP range43.130-43.166.x.x / 49.51.x.x / 162.62.x.x / 170.106.x.xAS132203 TencentAdditional Tencent Cloud campaign IP clusters
ASNAS132203Active threatTencent Cloud — primary campaign IP provider
User-Agentkali365-live/1.0.0Active threatOctoLink Live Electron app — present in Microsoft sign-in logs
App IDd3590ed6-52b3-4102-aeff-aad2292ab01cMaliciousMicrosoft Office app client ID abused for device code flow
Telegram Bot@NovosibyrskyMoneyBot (8535071077)Active exfilCredential exfiltration bot — token leaked by Arctic Wolf
TelegramChat group -5035652280ActiveDelivery supergroup for all captured credentials
Hashfebb622cd9eeb5c8860dcef4cbfd4b74InfrastructureVALIDIN banner hash (cross-campaign fingerprint)
TLS SHA16894a51278ec89118276c2dd2dc36e6f9ea2790aInfrastructureTLS certificate fingerprint (cross-campaign)
Evidence
Kali365 WHOIS serverHold + securehubcloud.com clientHold evidence
WHOIS output confirming kali365.xyz serverHold (registry seizure) and securehubcloud.com clientHold (NameSilo registrar action) — both seized as of 2026-08-19 · Sergiu Vincze OSINT · sevinhub.com/osint-016
Kali365 infrastructure map — Tencent Cloud IPs, BL Networks panel, tracking pixel
Live infrastructure check: 90 Tencent Cloud operator IPs (AS132203), BL Networks panel (199.91.220.111 nginx alive), tk.mowell.tech tracking pixel (HTTP 405 ACTIVE) · Sergiu Vincze OSINT · sevinhub.com/osint-016
tk.mowell.tech live browser verification — JSON API response confirms active tracking backend
Live browser verification: tk.mowell.tech returns {"msg":"invalid uri"} — custom JSON API actively running 3 months post-FBI-PSA closure · Captured 2026-08-19 · Sergiu Vincze OSINT · sevinhub.com/osint-016
Live IOC Status
Live Status — Automated HEAD checks
Loading…
Previous: Case 015 — Klarna Refund PhaaS Next: Case 017 — Ghost Stadium FIFA Visa Fraud
SevinOS BLE Radar