P1 Critical
PhaaS Platform
OAuth Token Hijack
MFA Bypass
FBI PSA I-052126
Domain Seizure
Kali365 — Microsoft 365 OAuth Device Code PhaaS
FBI PSA · Dual Domain Seizure · 90 Tencent Cloud IPs · Telegram Bot Leak
FBI-flagged Phishing-as-a-Service platform distributing Microsoft 365 OAuth token hijacking kits via Telegram since February 2026. The kit abuses device code authentication flow and AiTM reverse proxy to capture OAuth refresh tokens and session cookies without intercepting user passwords or MFA codes — granting persistent access to Outlook, Teams, OneDrive, and SharePoint admin portals. Approximately 500 affiliates, $200K–$350K subscription revenue, fake FBI-day closure, then continued operations under "Green Octopus" rebrand.
Kali365 / Green Octopus
PhaaS
Microsoft 365
OAuth Device Code
AiTM
MFA Bypass
kali365.xyz serverHold
securehubcloud.com clientHold
AS132203 Tencent
BL Networks Wyoming
Telegram Exfil
500 Affiliates
OxaPay Crypto
T1528 · T1111 · T1566
Status
serverHold (Seized)
Affiliates
~500 by May 2026
Revenue (Est.)
$200K–$350K
Campaign IPs
90+ (AS132203)
Kali365 operates as a tiered subscription PhaaS platform distributed via Telegram since February 2026, first catalogued by Palo Alto Unit42 on 2026-04-24. At $250/month paid in Bitcoin or USDT (via OxaPay gateway), the platform attracted approximately 300 affiliates by end of March 2026 and 500+ by May 2026 before the FBI PSA triggered a theatrical shutdown. Revenue is estimated at $200K–$350K across the full February–June 2026 operation window.
The platform ships in three editions. E1 provides the base AiTM and device code kit with 33 lure templates targeting Microsoft 365 services (Teams, Outlook, SharePoint, OneDrive), DocuSign, Dropbox, Google Drive, and Adobe. E2 adds a post-compromise AI-BEC module with Exchange admin abuse, keyword monitoring for payment/invoice-related emails, and a contact harvester that extracts victim organization communications for downstream fraud. E3 is a reseller edition with self-service provisioning, enabling a multi-tier affiliate model where sub-affiliates purchase access via shared referral links.
The desktop component, branded "OctoLink Live" (also seen as "kali365-live" and later "Green Octopus 3.1.0"), is an Electron application that loads captured OAuth tokens and provides authenticated one-click access to victim Outlook, OneDrive, and SharePoint portals without requiring any password or MFA interaction. A companion tool, "OctoLink Sender," uses the Microsoft Graph API to send lateral phishing from compromised mailboxes at 2,500 emails per token per day, with burst limiting (80 sends with 120-second cooldowns) and human-like jitter (5–12 second pauses every 12–19 sends) to evade mail flow anomaly detection.
"Ghost mode" automatically removes MFA notifications, password change alerts, and sign-in warning emails from victim inboxes, suppressing victim awareness of the compromise. The full device code authorization flow from lure delivery to token capture completes in approximately 42 seconds.
Edition Capabilities
─────────────────────────────────────────────────────────
E1 Base AiTM + Device Code, 33 lure templates, token vault
E2 BEC AI-BEC analysis, Exchange admin, keyword alerting
E3 Reseller Self-service provisioning, sub-affiliate management
Price $250 USD / 30 days
Currencies BTC, USDT (Tron network) via OxaPay
Affiliates ~300 March 2026 → ~500+ May 2026
Revenue est. $200,000 – $350,000 (Feb–Jun 2026)
Wallet moved ~$128K USDT off-chain via centralized exchanges
App name OctoLink Live / Green Octopus 3.1.0
User-Agent kali365-live/1.0.0
MS Client ID d3590ed6-52b3-4102-aeff-aad2292ab01c (Office app)
Session model persist:svc-{tokenId}-{service} (Electron partition)
Daily cap 2,500 emails per stolen token
Burst pattern 80 sends → 120s cooldown
Jitter 5–12s pause every 12–19 sends (human simulation)
Ghost mode actively suppresses MFA alerts, password change emails, and sign-in notifications from victim inboxes. Victims have no visibility of the compromise. OAuth refresh tokens provide access for months without requiring re-authentication.
WHOIS inspection reveals that both primary Kali365 infrastructure domains have been placed on hold by NameSilo, LLC. The original platform domain kali365.xyz carries serverHold status, indicating a registry-level seizure — typically issued under law enforcement coordination or ICANN abuse action. The panel domain securehubcloud.com, the migration infrastructure registered on May 16, 2026 (three days before the FBI PSA), carries clientHold status, indicating a registrar-initiated hold by NameSilo following the FBI publication.
The branding timeline shows rapid iteration: kali365.xyz → octopi365.com → blackoctopusking.live (announced May 7, 2026) → securehubcloud.com (registered May 16, 2026). The operators notified customers on May 21, 2026 — the same day the FBI PSA published — that they were "officially closing the website and discontinuing operations." Intelligence from SpyCloud and Huntress confirms activity continued post-announcement under the "Green Octopus" brand.
SSL certificate transparency for securehubcloud.com shows 7 confirmed subdomains provisioned via Let's Encrypt (E8/E7 chains) and Sectigo within a 3-day window. The origin.securehubcloud.com subdomain resolved directly to the BL Networks panel IP 66.179.30.87 before Cloudflare proxying was applied, exposing the backend hosting provider. The privacy-protected WHOIS registrant (PrivacyGuardian.org, Phoenix AZ) is consistent with all previous Kali365 domain registrations.
Creation Date 2026-04-18T17:32:26Z
Registrar NameSilo, LLC
Name Servers NAYA.NS.CLOUDFLARE.COM / DAKOTA.NS.CLOUDFLARE.COM
Status serverHold ← REGISTRY SEIZURE
Status clientTransferProhibited
Live Check HTTP:000 TIMEOUT/DEAD
Creation Date 2026-05-16T19:02:44Z
Registrar NameSilo, LLC
Registrant PrivacyGuardian.org / 1928 E. Highland Ave. Phoenix AZ
Name Servers JULIAN.NS.CLOUDFLARE.COM / LUCY.NS.CLOUDFLARE.COM
Status clientHold ← NAMESILO REGISTRAR ACTION
Updated 2026-05-21T21:40:13Z (same day as FBI PSA)
Cert 1 issued 2026-05-16 (Let's Encrypt E8)
Cert 2 issued 2026-05-19 (Let's Encrypt E7)
Cert 3 issued 2026-05-19 (Sectigo DV E36)
Subdomains origin / boss / api / panel / www / *.securehubcloud.com
Backend IP 66.179.30.87 (BL Networks, Sheridan WY — via origin subdomain)
2026-02-15 First branded "Kali365" capture observed
2026-04-18 kali365.xyz registered (NameSilo)
2026-05-07 Migration announced → blackoctopusking.live
2026-05-14 Source code updated: "Green Octopus 3.1.0"
2026-05-16 securehubcloud.com registered (new panel)
2026-05-21 "Official closure" — posted FBI PSA then announced shutdown
→ Activity confirmed CONTINUED post-announcement
kali365.xyz serverHold — DEAD
securehubcloud.com clientHold — DEAD
blackoctopusking.live No DNS record — DEAD
octopi365.com No response — DEAD
Both kali365.xyz (serverHold) and securehubcloud.com (clientHold) are confirmed seized at NameSilo as of the investigation date. The fake "closure" announcement synchronized with the FBI PSA did not end operations — the platform continued under Green Octopus branding until infrastructure was seized.
Huntress published 90 confirmed Tencent Cloud IPs used by Kali365 affiliates to conduct device code authentication attempts against victim Microsoft 365 accounts. All 90 IPs fall within AS132203 (TENCENT-NET-AP-CN, Tencent Building, Kejizhongyi Avenue, Shenzhen, CN), predominantly in the CIDR range 43.173.64.0/18 with additional clusters in 43.130.x.x, 43.131.x.x, 43.135.x.x, 43.153.x.x, 43.157.x.x, 43.159.x.x, 43.165.x.x, 43.166.x.x, 49.51.x.x, 162.62.x.x, and 170.106.x.x. These IPs appear in Microsoft Unified Audit Log (UAL) entries as the sources of successful device code authentication grants.
The operator control panel ran on 66.179.30.87 (BL Networks LLC, Sheridan, Wyoming, abuse: admin@blnwx.com) before Cloudflare proxying. This IP is now dead. A secondary BL Networks IP, 199.91.220.111 (CIDR 199.91.220.0/23, NetName BNL-77), returns nginx/1.24.0 Ubuntu on all paths with HTTP 404 — server alive, panel content stripped. This is consistent with panel migration or takedown response.
The 126-host cluster documented by Arctic Wolf (active May 6–27, 2026) was deployed as a single backend rotated across disposable front-end domains, enabling rapid campaign regeneration after domain seizures. Cloudflare Workers and Pages.dev instances handled lure routing, with discovered worker patterns matching [a-z]{5}-[a-z]{4}-[a-z0-9]{4} naming conventions across multiple Cloudflare accounts.
ASN AS132203 TENCENT-NET-AP-CN
Primary CIDR 43.173.64.0/18 (~16,384 IPs, heavily abused)
Additional 43.130.x.x, 43.131.x.x, 43.135.x.x, 43.153.x.x
43.157.x.x, 43.159.x.x, 43.165.x.x, 43.166.x.x
49.51.x.x, 162.62.x.x, 170.106.x.x
Sample IPs 43.131.0.54, 43.153.2.249, 43.157.64.101, 170.106.119.249
Panel IP 66.179.30.87 — DEAD (post-seizure)
Secondary IP 199.91.220.111 — nginx/1.24.0 Ubuntu HTTP:404
CIDR 199.91.220.0/23 (BNL-77, BL Networks)
Abuse admin@blnwx.com / +1-307-317-1097
Open ports 22 (OpenSSH 9.9p1) · 80 · 443 · 8443 (operator panel)
/dash/auth Operator login
/dash/tokens Stolen OAuth token vault
/dash/lures AI lure template manager
/dash/send-jobs/{id} Live campaign sender
/dash/bec/analyze AI-BEC invoice/payment filter
/dash/highvalue High-value target triage
/dash/my-worker Cloudflare Worker management
/dash/exchange Exchange admin abuse module
/admin/users Affiliate management
/admin/billing Subscription billing
UAL anomaly Tencent AS132203 IP in device code auth grant
UAL anomaly Refresh token grant WITHOUT interactive sign-in
UAL anomaly Python-requests UA from operator ASN
UAL anomaly Electron UA in Microsoft sign-in logs
Mail anomaly Non-existent message GET (404s post-send pattern)
The 90 Tencent Cloud IPs are the detection anchor. Any Microsoft 365 sign-in log showing a device code authorization grant from AS132203 (43.130-43.173.x.x range) should be treated as a confirmed Kali365 compromise. Refresh token grants with no preceding interactive sign-in are the second key indicator.
Arctic Wolf researchers, during active investigation of the Kali365 operator expansion into MAX Messenger (Russian state-backed messaging platform), documented the Telegram exfiltration bot credential in full. The bot @NovosibyrskyMoneyBot (internal name: sova_novosibirsk_bot) receives stolen phone numbers, one-time passwords, and 2FA passwords captured from victims across all supported phishing templates.
The bot name is a direct Russian language reference: "Novosibirsk" is the third-largest city in Russia (Siberia), and "Novosibirsky Money" maps to a known Russian-language underground financial fraud context. The "sova" prefix (Russian for "owl") is a recurring theme in Russian-speaking cybercrime infrastructure. This operator naming convention strongly suggests a Russian-speaking threat actor group operating out of or affiliated with Siberia-based criminal networks.
The leaked token format 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg follows the standard Telegram Bot API format (bot_id:secret). The numeric prefix 8535071077 is the bot user ID. The chat group -5035652280 (negative ID indicating a group or supergroup, not a direct chat) is the delivery channel for all exfiltrated credentials.
The MAX Messenger phishing flow the bot supports captures Russian phone numbers (+7 prefix), legitimate MAX SMS/push OTPs, and 2FA passwords in sequence — a complete account takeover chain for Russian consumers alongside the primary M365 targeting.
Bot Username @NovosibyrskyMoneyBot
Internal name sova_novosibirsk_bot
Bot Token 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg
Bot ID 8535071077
Chat Group ID -5035652280 (supergroup — credential delivery channel)
Exfil data Phone numbers, OTPs, 2FA passwords, account recovery codes
Bot name ref Novosibirsk = 3rd-largest Russian city (Siberia)
Prefix "sova" Russian for "owl" — recurring RU-speaking cybercrime tag
Language Russian-speaking threat actor group (assessed)
Pixel domain tk.mowell.tech — HTTP:405 ACTIVE
Tracking ID 906596682876295936
CNAME chain tk.mowell.tech → https-api.bytegle.tech
Bytegle ASN Alibaba Cloud (AWS Route53 NS) — China-routed
Pixel IPs 141.11.124.140 / 162.141.119.128 / 143.20.90.69
mowell.tech reg 2023-07-28, Alibaba Cloud HiChina (updated 2025-06-17)
Gateway OxaPay (crypto payment processor)
Primary assets BTC, USDT (Tron TRC-20 network)
Cashout ~$128K USDT consolidated and moved off-chain
Routing Traced to flagged illicit-finance wallet cluster
The Telegram bot token is live intelligence — it has been reported to Telegram's abuse channel and to EC3/Europol. The token was documented by Arctic Wolf and is referenced here from their published report. Reporting this to Telegram Law Enforcement enables chat log extraction under legal process. The chat group ID (-5035652280) contains captured credential flows from all Kali365 affiliate campaigns.
Arctic Wolf documented a significant expansion of the Kali365 operator's targeting scope beyond Microsoft 365, establishing this as a multi-platform identity theft operation. The operator deployed phishing pages targeting MAX Messenger (Russian state-backed messaging platform), Okta SSO, Xerox DocuShare, GMX (German email), LiveDrive (UK cloud storage), Mail.ru, Yandex Disk, Odnoklassniki, and AWS (mimicked endpoint naming). The Russian-platform targeting (MAX, Mail.ru, Yandex, Odnoklassniki) alongside Siberia-branded Telegram infrastructure corroborates the Russian-speaking operator hypothesis.
The MAX Messenger phishing domain greatness-marketing[.]top deployed a prize-claim social engineering lure. The backend attachedfile[.]com (39 subdomains observed, registered 2026-02-14 by Hostinger, last updated 2026-07-21) served as a persistent Cloudflare-proxied front for lure hosting across multiple campaigns. The domain predates Kali365's April public launch by two months, suggesting earlier-stage infrastructure preparation or a shared prior operation.
Detection fingerprints identified across all expanded deployments: HTML loader text "Preparing your secure document..." shared across all lure templates, and Cloudflare Workers with same-origin fetch pattern data-form-o5pu[.]p-ntz8agp6[.]workers[.]dev. The VALIDIN banner hash febb622cd9eeb5c8860dcef4cbfd4b74 and TLS certificate SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a provide consistent infrastructure fingerprinting across all Kali365/Green Octopus deployments.
ANY.RUN analysis identified 34 phishing domains in the Kali365 campaign infrastructure, predominantly using .de TLD — strongly clustering on German-sounding generic names as lure delivery domains, with a secondary cluster on workers.dev Cloudflare-hosted templates.
Live verification (2026-08-19): Navigating directly to tk.mowell.tech in a browser returns {"msg":"invalid uri"} — a structured JSON error from custom application code, not a generic web server response. This is definitive proof the tracking backend is still running live business logic. The server is not a parked page or residual nginx default — it is an active API endpoint waiting for victim tracking tokens appended to specific URI paths. The operators shut down the phishing front-ends but left their data collection engine completely running. Three months after the FBI PSA "closure," the tracking infrastructure is still operational.
MAX Messenger Russian state-backed messenger (phone OTP capture flow)
Okta SSO Enterprise SSO identity provider
Xerox DocuShare Document management (enterprise supply chain vector)
GMX German email provider
LiveDrive UK cloud storage
Mail.ru Russian email/cloud
Yandex Disk Russian cloud storage
Odnoklassniki Russian social network (VKontakte equivalent)
AWS Mimicked AWS endpoint naming
HTML loader "Preparing your secure document…"
Worker pattern data-form-o5pu[.]p-ntz8agp6[.]workers[.]dev
Banner hash febb622cd9eeb5c8860dcef4cbfd4b74 (VALIDIN)
TLS SHA1 6894a51278ec89118276c2dd2dc36e6f9ea2790a
API endpoints /api/generate?lure=ID / /api/status/N / /api/lure-config/ID
flexiscalesystems.de guardedwebsolutions.de
reputationboosters.de prowebsitemakers.de
onlinebrandinghub.de modernwebbalance.de
marketadaptabletech.de brandswithintegrity.de
turnideastoresults.de reliablebusinesstech.de
performancereputation.de trustinbrands.de [+23 more]
tryingdocusign.pages.dev HTTP:000 (suspended)
sharepoint-81c.pages.dev HTTP:403 (CF block)
sharepoint-63m.pages.dev HTTP:403 (CF block)
cloud-microsoft-drive-for-business.workers.dev (discovered)
attachedfile.com HTTP:404 (CF alive, registered 2026-02-14, Hostinger)
greatness-marketing.top MAX Messenger prize lure (CF, dead)
Request GET https://tk.mowell.tech/ (browser, Belgian IP)
Response {"msg":"invalid uri"}
Meaning Custom JSON API running — expects victim token in URI path
e.g. /track/{victim_id} or /pixel/{token}
Not nginx default This is active application code — Node.js or Python backend
Conclusion Tracking data collection engine still LIVE 3 months post-"closure"
FBI + Huntress + Arctic Wolf missed this — infrastructure incomplete takedown
The .de domain cluster (generic German-sounding business names) is a deliberate anti-detection strategy. Registrars and threat intel feeds are less likely to flag "modernwebbalance.de" or "trustinbrands.de" as malicious without active investigation. These domains serve as lure delivery points that redirect to the actual phishing template hosted on Cloudflare Workers.
The Kali365 attack chain exploits the OAuth 2.0 Device Authorization Grant (RFC 8628), a flow designed for input-constrained devices like smart TVs, printers, and IoT hardware. The attacker initiates the flow against their own registered application (Microsoft client ID d3590ed6-52b3-4102-aeff-aad2292ab01c, the Office app identity), obtains a user_code valid for 15 minutes, and embeds it in a phishing lure. When the victim visits microsoft.com/devicelogin (a legitimate Microsoft URL) and enters the code, the attacker's application receives the OAuth access_token and refresh_token directly from Microsoft's authorization server.
No phishing proxy is needed. No fake login page. The victim interacts only with real Microsoft infrastructure. MFA completes legitimately. The attacker's session is authorized before the victim closes the browser. The refresh token provides access for months without re-authentication, enabling persistent Outlook, Teams, OneDrive, and SharePoint access.
The E2 post-compromise module then weaponizes the compromised mailbox: a contact harvester extracts all communications, a BEC keyword engine flags emails matching payment, invoice, wire transfer, and accounting terms, and the AI template generator crafts reply-chain phishing messages using the victim's real email history and writing style. The "Ghost mode" suppresses all Microsoft security notifications from the victim's inbox, maintaining stealth for the full access window.
The parallel AiTM path (Evilginx2 reverse-proxy "ginX" instances) captures ESTSAUTH session cookies and OAuth artifacts from interactive MFA sessions, providing an alternative capture method for targets that do not follow the device code lure.
Step 1 Attacker initiates device code flow against MS App ID:
POST https://login.microsoftonline.com/common/oauth2/v2.0/devicecode
client_id=d3590ed6-52b3-4102-aeff-aad2292ab01c
Step 2 Microsoft returns: user_code (8-char alphanum), device_code, verification_uri
verification_uri = https://microsoft.com/devicelogin (LEGITIMATE URL)
Step 3 Phishing lure delivered via Canva-hosted page / .de lure domain
"Sign in to share document — visit microsoft.com/devicelogin, enter: [code]"
Step 4 Victim navigates to real Microsoft page, enters attacker's user_code
Victim completes legitimate MFA — interacting only with Microsoft servers
Step 5 Attacker polls /oauth2/v2.0/token — receives access_token + refresh_token
Compromise complete in ~42 seconds from code entry
Step 6 OctoLink Live app loads token — one-click access to Outlook / SharePoint
Step 7 Ghost mode: MFA alerts, password change emails, sign-in warnings deleted
Step 8 E2 BEC module: contact harvest → keyword filter → reply-chain phishing
Method Evilginx2 instance proxies Microsoft login
Capture ESTSAUTH cookie + OAuth artifacts from interactive MFA session
Result Same persistent access, no device code required
T1566.002 Phishing — Spearphishing Link (initial lure delivery)
T1528 Steal Application Access Token (core technique)
T1111 Multi-Factor Authentication Interception (device code bypass)
T1539 Steal Web Session Cookie (AiTM path, ESTSAUTH)
T1567.002 Exfiltration Over Web Service — Telegram
T1583.001 Acquire Infrastructure — Domains (NameSilo, Cloudflare)
T1036 Masquerading (Office app client ID, Canva-hosted lures)
T1078.004 Valid Accounts — Cloud Accounts (persistent OAuth session)
T1564.008 Hide Artifacts — Email Hiding Rules (Ghost mode)
This attack technique requires no password. It requires no credential phishing. It bypasses MFA completely. The victim interacts only with legitimate Microsoft infrastructure. The only defense is restricting device code flow via Conditional Access Policy or blocking Microsoft OAuth app ID d3590ed6-52b3-4102-aeff-aad2292ab01c from authorization in organizational tenants.
Reporting
FBI / IC3 (existing PSA)
www.ic3.gov/complaint (PSA: I-052126-PSA)
Primary investigators. PSA published 2026-05-21. Any new infrastructure or affiliate activity supplements existing FBI case file.
CISA (Cybersecurity and Infrastructure Security Agency)
report@cisa.gov
US critical infrastructure targeting: construction, manufacturing, healthcare, government sectors explicitly documented as primary victims.
EC3 / Europol (EU cross-border PhaaS)
ec3@europol.europa.eu
EU victim clusters in Australia, India, Canada, Germany (GMX targeting). Multi-jurisdiction coordination needed.
CCB / SafeOnWeb Belgium
suspicious@safeonweb.be
Belgian awareness. GMX targeting and EU sector victims include Belgian enterprises. BEC module weaponizes compromised Belgian mailboxes for downstream attacks.
NameSilo (Registrar — both domains seized)
abuse@namesilo.com
Both kali365.xyz and securehubcloud.com are already on hold. Reporting confirms awareness and requests permanent suspension and domain transfer block.
BL Networks (Panel hosting provider)
admin@blnwx.com
199.91.220.111 (nginx alive, HTTP 404) remains under BL Networks control. Requesting full nullroute and account termination.
Telegram Law Enforcement / Abuse
abuse@telegram.org
Exfiltration bot @NovosibyrskyMoneyBot (bot ID 8535071077) with documented credential delivery channel. Token: 8535071077:AAFus1ccm-puZ2htZkpKP_UyZfp3FTHFCzg
Investigation Method
Phase 1 — Target Discovery: FBI/IC3 Public Service Announcement I-052126-PSA (2026-05-21) flagged Kali365 as an active PhaaS distributing Microsoft 365 OAuth token hijacking kits via Telegram. Investigation initiated 2026-08-19 following a YouTube video by John Hammond covering the FBI PSA.
Phase 2 — Technical Intelligence Gathering: Cross-referenced FBI PSA with published research from Huntress (device code ecosystem deep-dive), SpyCloud (anatomy + branding timeline), Arctic Wolf (multi-platform expansion), Palo Alto Unit42 (April 2026 first report), ANY.RUN (malware trends + domain list), Todyl (infrastructure enumeration), and Doppel (PhaaS overview). Pulled Huntress GitHub IOC CSV (283 lines, 90 IPs).
Phase 3 — Live Infrastructure Verification: HTTP HEAD checks on all known domains. kali365.xyz: HTTP:000 DEAD. securehubcloud.com: HTTP:000 DEAD. blackoctopusking.live: No DNS record. 199.91.220.111: nginx/1.24.0 Ubuntu, HTTP:404 (server alive). tk.mowell.tech: HTTP:405 ACTIVE (tracking pixel). sharepoint-81c/63m.pages.dev: HTTP:403 (Cloudflare blocked). attachedfile.com: HTTP:404 (Cloudflare).
Phase 4 — WHOIS and Certificate Transparency: WHOIS confirmed kali365.xyz serverHold (registry seizure) and securehubcloud.com clientHold (NameSilo registrar action, updated 2026-05-21 = FBI PSA day). crt.sh enumeration of securehubcloud.com revealed 7 subdomains and backend IP 66.179.30.87 (BL Networks Wyoming) via origin subdomain before Cloudflare proxying was applied.
Phase 5 — ASN and Reverse IP Analysis: Confirmed AS132203 (Tencent Cloud) as primary campaign IP block hosting 90 operator IPs. BL Networks secondary IP 199.91.220.111 confirmed alive via direct HTTP check (nginx/1.24.0, all paths 404 — panel stripped).
Phase 6 — IOC Consolidation and MITRE Mapping: Extracted all IOCs from public intelligence sources. Mapped 8 MITRE ATT&CK techniques. Documented tracking pixel (tk.mowell.tech) as live remaining infrastructure. Compiled reporting package for FBI/IC3, EC3/Europol, CCB, NameSilo, BL Networks, and Telegram abuse.
IOC Table
| Type |
Indicator |
Status |
Notes |
| Domain | kali365.xyz | SEIZED (serverHold) | Primary platform domain — NameSilo registry action |
| Domain | securehubcloud.com | SEIZED (clientHold) | Migration panel domain — NameSilo registrar action 2026-05-21 |
| Domain | blackoctopusking.live | DEAD | Rebranding migration domain (announced 2026-05-07) |
| Domain | octopi365.com | DEAD | Earlier brand variant |
| Domain | attachedfile.com | CF 404 | Lure hosting — registered 2026-02-14, Hostinger, 39 subdomains |
| Domain | greatness-marketing.top | DEAD | MAX Messenger prize phish lure |
| Domain | tk.mowell.tech | ACTIVE (HTTP 405) | Tracking pixel — CNAME bytegle.tech (Alibaba Cloud) |
| Domain | bluefoodtruths.xyz | Unknown | .de lure cluster (ANY.RUN — 34 domains identified) |
| Domain | flexiscalesystems.de + 33 .de domains | Unknown | Lure delivery domains — generic German branding |
| Domain | sharepoint-81c.pages.dev | HTTP 403 (CF blocked) | Cloudflare Pages phishing template |
| Domain | sharepoint-63m.pages.dev | HTTP 403 (CF blocked) | Cloudflare Pages phishing template |
| IP | 66.179.30.87 | DEAD | Panel server — BL Networks Wyoming (admin@blnwx.com) |
| IP | 199.91.220.111 | nginx alive (404) | BL Networks Wyoming — panel stripped, server alive |
| IP | 141.11.124.140 | ACTIVE | Tracking pixel IP (bytegle.tech) |
| IP range | 43.173.64.0/18 | AS132203 Tencent | Primary campaign operator IP CIDR (90 IPs confirmed) |
| IP range | 43.130-43.166.x.x / 49.51.x.x / 162.62.x.x / 170.106.x.x | AS132203 Tencent | Additional Tencent Cloud campaign IP clusters |
| ASN | AS132203 | Active threat | Tencent Cloud — primary campaign IP provider |
| User-Agent | kali365-live/1.0.0 | Active threat | OctoLink Live Electron app — present in Microsoft sign-in logs |
| App ID | d3590ed6-52b3-4102-aeff-aad2292ab01c | Malicious | Microsoft Office app client ID abused for device code flow |
| Telegram Bot | @NovosibyrskyMoneyBot (8535071077) | Active exfil | Credential exfiltration bot — token leaked by Arctic Wolf |
| Telegram | Chat group -5035652280 | Active | Delivery supergroup for all captured credentials |
| Hash | febb622cd9eeb5c8860dcef4cbfd4b74 | Infrastructure | VALIDIN banner hash (cross-campaign fingerprint) |
| TLS SHA1 | 6894a51278ec89118276c2dd2dc36e6f9ea2790a | Infrastructure | TLS certificate fingerprint (cross-campaign) |
Evidence
WHOIS output confirming kali365.xyz serverHold (registry seizure) and securehubcloud.com clientHold (NameSilo registrar action) — both seized as of 2026-08-19 · Sergiu Vincze OSINT · sevinhub.com/osint-016
Live infrastructure check: 90 Tencent Cloud operator IPs (AS132203), BL Networks panel (199.91.220.111 nginx alive), tk.mowell.tech tracking pixel (HTTP 405 ACTIVE) · Sergiu Vincze OSINT · sevinhub.com/osint-016
Live browser verification: tk.mowell.tech returns {"msg":"invalid uri"} — custom JSON API actively running 3 months post-FBI-PSA closure · Captured 2026-08-19 · Sergiu Vincze OSINT · sevinhub.com/osint-016
Live IOC Status
Live Status — Automated HEAD checks
Loading…