🔍 𝗧𝗿𝗮𝗰𝗸𝗶𝗻𝗴 𝗞𝗮𝗹𝗶𝟯𝟲𝟱 𝗜𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 𝗘𝘃𝗼𝗹𝘂𝘁𝗶𝗼𝗻
Building on ZeroBEC's excellent research into 𝗞𝗮𝗹𝗶𝟯𝟲𝟱 𝗥𝗶𝗻𝗴𝗲𝗿, and based on intelligence gathered through @anyrun_app , I observed that Kali365 threat actors began leveraging a more sophisticated infrastructure chain as early as 𝗝𝘂𝗻𝗲 𝟮𝟬𝟮𝟲.
The attack flow abuses trusted cloud services to increase legitimacy and evade detection:
𝗚𝗼𝗼𝗴𝗹𝗲 𝗦𝗶𝘁𝗲𝘀 (𝘁𝗿𝘂𝘀𝘁𝗲𝗱 𝗹𝘂𝗿𝗲) → 𝗚𝗼𝗼𝗴𝗹𝗲 𝗥𝗲𝗱𝗶𝗿𝗲𝗰𝘁𝗼𝗿 → 𝗔𝗣𝗜 𝗚𝗮𝘁𝗲𝘄𝗮𝘆 → 𝗖𝗹𝗼𝘂𝗱𝗳𝗹𝗮𝗿𝗲-𝗽𝗿𝗼𝘁𝗲𝗰𝘁𝗲𝗱 𝗞𝗮𝗹𝗶𝟯𝟲𝟱 𝗵𝗼𝘀𝘁
The initial lure is hosted behind a trusted 𝗚𝗼𝗼𝗴𝗹𝗲 𝗦𝗶𝘁𝗲𝘀 wrapper before victims are redirected through multiple intermediary services, ultimately landing on the actor-controlled Kali365 infrastructure protected by Cloudflare.
🛡️ 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗥𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗮𝘁𝗶𝗼𝗻
Security teams should review 𝗘𝗺𝗮𝗶𝗹𝗨𝗿𝗹𝗜𝗻𝗳𝗼 telemetry and look for unusual spikes in:
𝚜𝚒𝚝𝚎𝚜.𝚐𝚘𝚘𝚐𝚕𝚎.𝚌𝚘𝚖/𝚟𝚒𝚎𝚠
with:
𝙸𝚜𝙵𝚒𝚛𝚜𝚝𝙲𝚘𝚗𝚝𝚊𝚌𝚝 = 𝚝𝚛𝚞𝚎
Such activity may indicate users are being exposed to previously unseen Google Sites–based phishing lures and could provide an early detection opportunity for Kali365-related campaigns. 🫡
🎯 𝗜𝗻𝗱𝘂𝘀𝘁𝗿𝗶𝗲𝘀 𝗧𝗮𝗿𝗴𝗲𝘁𝗲𝗱 𝗯𝘆 𝗧𝗵𝗶𝘀 𝗞𝗮𝗹𝗶𝟯𝟲𝟱 𝗖𝗮𝗺𝗽𝗮𝗶𝗴𝗻 (𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝗣𝗿𝗲𝗰𝗲𝗱𝗲𝗻𝗰𝗲 𝗢𝗿𝗱𝗲𝗿)
1. Technology
2. Managed Security Service Providers (MSSPs)
3. Manufacturing
4. Healthcare
5. Financial Services
#KQL #Phishing #Kali365 #ThreatIntelligence
#ThreatHunting #MicrosoftDefenderXDR
UPDATE 🠒 Latest MS Defender’s RoguePlanet patch may have introduced a new problem.
Researcher 'Chaotic Eclipse' says Defender can cache a massive Zone.Identifier ADS file and exhaust disk space when a system visits a custom SMB server.
They reproduced it on Windows 11 25H2 and Windows Server 2025.
Read: https://t.co/L6kiXGO9DH
@arekfurt from my understanding they say only that you should patch your systems. And this is not the first time that people don‘t see it as a big problem and doesn‘t care about patching or they could not because of issues in the environment
🚨 Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes
Source: https://t.co/A7kA57hhgG
Hackers are increasingly abusing trusted enterprise platforms such as Microsoft Teams and Google Drive to deploy stealthy remote access malware, with a newly observed campaign leveraging social engineering and cloud-based command-and-control to evade detection.
Within minutes, the threat actor delivered a Java-based remote access trojan known as Nimbus RAT, completing the compromise in under 20 minutes. The attack followed a structured, repeatable kill chain, highlighting the growing operational maturity of these campaigns.
#cybersecuritynews
@0ddshell@cyb3rops Most of our affected devices got the certs directly reinstalled by Microsoft CTL, after the defender has deleted it. Checked the Timeline of some affected devices which showing me that deleting and restoring running in the same second.
#Citrix 2305: When you create a catalog, a Hybrid Azure Active Directory joined identity type, is now available in Machine Identities. https://t.co/jNfC0txfiZ