From Kali365 to a Wider Device-Code Phishing Ecosystem: A Webamon Intel Pivot Chain
📰 Medium · Cybersecurity
Learn about the Kali365 device-code phishing ecosystem and how to identify its tactics, techniques, and procedures (TTPs) to improve cybersecurity defenses
Action Steps
- Analyze the lure page titles and URLs to identify potential phishing attempts
- Investigate the Command and Control (C2) hosts to understand the attacker's infrastructure
- Examine the 'Enter code' sets to distinguish genuine device-code phish from legitimate authentication requests
- Pivot off the C2 host to expand the investigation and identify related phishing campaigns
- Monitor for 'Shared document' lure families and DocuSign/OneDrive lookalike domains to detect potential phishing attacks
Who Needs to Know This
Security professionals and incident responders can benefit from understanding the Kali365 phishing ecosystem to enhance their organization's cybersecurity posture and protect against similar threats
Key Insight
💡 The Kali365 phishing ecosystem uses various tactics, including lure page titles, C2 hosts, and 'Enter code' sets, to trick victims into divulging sensitive information
Share This
🚨 New research reveals the Kali365 device-code phishing ecosystem! 🚨 Learn how to identify its TTPs and improve your cybersecurity defenses #cybersecurity #phishing
Key Takeaways
Learn about the Kali365 device-code phishing ecosystem and how to identify its tactics, techniques, and procedures (TTPs) to improve cybersecurity defenses
Full Article
Title: From Kali365 to a Wider Device-Code Phishing Ecosystem: A Webamon Intel Pivot Chain
URL Source: https://medium.com/@nouman136/from-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66?source=rss------cybersecurity-5
Published Time: 2026-07-19T18:05:14Z
Markdown Content:
[Sitemap](https://medium.com/sitemap/sitemap.xml)
[Open in app](https://play.google.com/store/apps/details?id=com.medium.reader&referrer=utm_source%3DmobileNavBar&source=---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40ahmi10917%2Ffrom-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)
[](https://medium.com/?source=---top_nav_layout_nav-----------------------------------------)
Get app
[Write](https://medium.com/m/signin?operation=register&redirect=https%3A%2F%2Fmedium.com%2Fnew-story&source=---top_nav_layout_nav-----------------------new_post_topnav------------------)
[Search](https://medium.com/search?source=---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40ahmi10917%2Ffrom-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)

1. [Starting point: the lure page title](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#8e59 "Starting point: the lure page title")
2. [Narrowing the “Enter code” set to genuine device-code phish](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#4134 "Narrowing the “Enter code” set to genuine device-code phish")
3. [Pivoting off the C2 host](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#7d2e "Pivoting off the C2 host")
4. [Expanding the “Shared document” lure family](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#b2dc "Expanding the “Shared document” lure family")
5. [Family A — Direct credential-capture forms](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#7662 "Family A — Direct credential-capture forms")
6. [Family B — Bot-gated Workers/Pages redirector](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#0fe7 "Family B — Bot-gated Workers/Pages redirector")
7. [Family C — DocuSign/OneDrive lookalike domains](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#d606 "Family C — DocuSign/OneDrive lookalike domains")
8. [Conclusion](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#d62c "Conclusion")
# From Kali365 to a Wider Device-Code Phishing Ecosystem: A Webamon Intel Pivot Chain
[](https://medium.com/@nouman136?source=post_page---byline--9ac4ec763d66---------------------------------------)
[Nouman](https://medium.com/@nouman136?source=post_page---byline--9ac4ec763d66---------------------------------------)
Follow
5 min read
·
Just now
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fvote%2Fp%2F9ac4ec763d66&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40ahmi10917%2Ffrom-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66&user=Nouman&userId=829cd07e13cd&source=---header_actions--9ac4ec763d66---------------------clap_footer------------------)
[](https://medium.com/m/
URL Source: https://medium.com/@nouman136/from-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66?source=rss------cybersecurity-5
Published Time: 2026-07-19T18:05:14Z
Markdown Content:
[Sitemap](https://medium.com/sitemap/sitemap.xml)
[Open in app](https://play.google.com/store/apps/details?id=com.medium.reader&referrer=utm_source%3DmobileNavBar&source=---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40ahmi10917%2Ffrom-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)
[](https://medium.com/?source=---top_nav_layout_nav-----------------------------------------)
Get app
[Write](https://medium.com/m/signin?operation=register&redirect=https%3A%2F%2Fmedium.com%2Fnew-story&source=---top_nav_layout_nav-----------------------new_post_topnav------------------)
[Search](https://medium.com/search?source=---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40ahmi10917%2Ffrom-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)

1. [Starting point: the lure page title](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#8e59 "Starting point: the lure page title")
2. [Narrowing the “Enter code” set to genuine device-code phish](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#4134 "Narrowing the “Enter code” set to genuine device-code phish")
3. [Pivoting off the C2 host](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#7d2e "Pivoting off the C2 host")
4. [Expanding the “Shared document” lure family](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#b2dc "Expanding the “Shared document” lure family")
5. [Family A — Direct credential-capture forms](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#7662 "Family A — Direct credential-capture forms")
6. [Family B — Bot-gated Workers/Pages redirector](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#0fe7 "Family B — Bot-gated Workers/Pages redirector")
7. [Family C — DocuSign/OneDrive lookalike domains](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#d606 "Family C — DocuSign/OneDrive lookalike domains")
8. [Conclusion](https://medium.com/?source=post_page-----9ac4ec763d66---------------------------------------#d62c "Conclusion")
# From Kali365 to a Wider Device-Code Phishing Ecosystem: A Webamon Intel Pivot Chain
[](https://medium.com/@nouman136?source=post_page---byline--9ac4ec763d66---------------------------------------)
[Nouman](https://medium.com/@nouman136?source=post_page---byline--9ac4ec763d66---------------------------------------)
Follow
5 min read
·
Just now
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fvote%2Fp%2F9ac4ec763d66&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40ahmi10917%2Ffrom-kali365-to-a-wider-device-code-phishing-ecosystem-a-webamon-intel-pivot-chain-9ac4ec763d66&user=Nouman&userId=829cd07e13cd&source=---header_actions--9ac4ec763d66---------------------clap_footer------------------)
[](https://medium.com/m/
DeepCamp AI