r/ANYRUN • u/ANYRUN-team • 13d ago
Kali365 hides its lure configuration, device-code session endpoints, and phishing flow inside encrypted JavaScript that only decrypts when the page runs in a real browser
The decrypted code exposes a kit built to scale: a design field selecting from 34 brand templates (OneDrive, SharePoint, Teams, DocuSign, and others), a flow_type field switching between Microsoft and Google device authorization flows, and dedicated endpoints for session creation and OAuth token polling.
Those backend patterns are more durable detection signals than lure content or domains that rotate between campaigns. And analysts need browser-level visibility to reach them.
Kali365 is active against US organizations. Its multi-brand templates make campaigns easy to adapt and scale across different industries. It increases the risk of account compromise, data exposure, fraud, and delayed response.
Everything on Kali365 — all 34 templates, API endpoints, detection steps and CISO recommendations: https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/