Vibe-coded kits and a crowded market
The reason this technique has moved from a niche red team trick to something we now see weekly is that it has been packaged and sold.
Kali365 is the clearest example. First observed in April 2026 and the subject of an FBI IC3 advisory in May, it is a subscription phishing-as-a-service platform sold through Telegram, with dozens of built-in lures, token management, AI-generated business email compromise content and a companion desktop application that turns a stolen token into a live browser session inside the victim’s mailbox. Huntress, who reverse engineered it, describe the panel as vibe-coded. It has also appeared under the names Octopi365 and Freedom365, and has since expanded beyond Microsoft 365 to target AWS, Okta and other identity platforms.
Kali365 is not an outlier, it is a template. Forg365 surfaced in July, sold via Telegram with a five day free trial and then $400 a month or $3,800 a year, offering AI-assisted lure generation, adversary-in-the-middle routing, bot evasion, token vaulting and a browser extension for persistent single sign-on access. Researchers have documented Jalisco, OmegaLord, EvilTokens, Venom and CYB3R appearing over the same period, and long-established kits including Sneaky 2FA and Greatness have bolted device code support onto their existing panels.
The common factor is that AI-assisted development has collapsed the cost of entering this market. Building a credible phishing platform used to require a developer. It now requires a prompt and a Telegram channel. That is why the names keep changing, why the panels look increasingly alike, and why the volume keeps climbing. It also lowers the skill floor for the buyer, because the operator workflow is now a dashboard rather than a toolchain.