Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Home/CyberSecurity News/FBI Warns Kali365 Phishing Attacks Steal Microsoft 365 Credentials, Bypass MFA
CyberSecurity News

FBI Warns Kali365 Phishing Attacks Steal Microsoft 365 Credentials, Bypass MFA

Key Takeaways The FBI has issued a warning about Kali365, a new Phishing-as-a-Service (PhaaS) platform. Kali365 specifically targets Microsoft 365 users to steal OAuth tokens, enabling attackers to...

Emy Elsamnoudy
Emy Elsamnoudy
May 22, 2026 3 Min Read
63 0

Key Takeaways

  • The FBI has issued a warning about Kali365, a new Phishing-as-a-Service (PhaaS) platform.
  • Kali365 specifically targets Microsoft 365 users to steal OAuth tokens, enabling attackers to bypass multi-factor authentication (MFA).
  • This platform leverages Microsoft’s legitimate device code authentication flow, making detection challenging.
  • Attackers gain persistent access to email, files, and communications without needing traditional credentials.

The Federal Bureau of Investigation (FBI) has released a public cybersecurity alert concerning Kali365, a sophisticated Phishing-as-a-Service (PhaaS) platform. This emerging threat is designed to compromise Microsoft 365 user accounts by illicitly acquiring access tokens, effectively circumventing multi-factor authentication (MFA) protocols.

Table Of Content

  • Key Takeaways
  • Kali365 PhaaS Targets Microsoft 365
  • What You Should Do

Kali365 is primarily disseminated through Telegram channels, providing a low-barrier entry point for threat actors. Subscribers to the service can initiate phishing campaigns with minimal technical expertise.

A significant departure from conventional credential-harvesting methods, Kali365 focuses on capturing OAuth tokens. This mechanism grants attackers enduring access to Microsoft 365 accounts without requiring the user’s username, password, or even their MFA codes.

The platform is equipped with several features that streamline the attack process for cybercriminals:

  • AI-driven generation of convincing phishing email templates that mimic legitimate services.
  • Automated tools for deploying and managing phishing campaigns.
  • Dashboards offering real-time tracking of victim engagement.
  • Integrated mechanisms for capturing OAuth tokens.

This comprehensive toolkit empowers even less-skilled attackers to execute large-scale, sophisticated phishing operations.

Kali365 PhaaS Targets Microsoft 365

The Kali365 attack methodology exploits Microsoft’s legitimate device code authentication flow to trick users into inadvertently authorizing malicious access. The process unfolds in several stages:

  • Lure: Victims receive deceptive phishing emails, often appearing to originate from Microsoft or trusted document-sharing services. These emails contain a device code and instructions prompting the user to take action.
  • Authorization: The user is then directed to an authentic Microsoft verification page, where they are instructed to input the provided device code.
  • Token Theft: By entering the code, the user unknowingly grants authorization for the attacker’s session, allowing the attacker to intercept OAuth access and refresh tokens.
  • Persistence: With these tokens, attackers can then access critical Microsoft 365 services such as Outlook, Teams, and OneDrive without needing to re-authenticate or trigger MFA.

This technique poses a significant risk because it weaponizes legitimate authentication workflows, making such intrusions considerably harder to detect through traditional security measures.

Today the FBI released a #PSA warning the public about Kali365—an emerging Phishing-as-a-Service (PhaaS) platform. Kali365, first seen in April 2026, enables cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without… pic.twitter.com/AalckpLVHG

— FBI Cyber Division (@FBICyberDiv) May 21, 2026

Identified under Alert Number I-052126-PSA and initially observed in April 2026, the Kali365 platform is rapidly gaining traction among cybercriminals due to its user-friendly interface and advanced capabilities.

Once attackers successfully gain access, they can perform a variety of malicious actions:

  • Read and exfiltrate sensitive emails.
  • Access and download confidential files stored in OneDrive.
  • Monitor and intercept communications via Microsoft Teams.
  • Maintain long-term persistence within the compromised environment using stolen refresh tokens.

Since this method avoids direct credential theft, it often bypasses conventional security alerts, potentially increasing the attacker’s dwell time within the victim’s network.

What You Should Do

The FBI and CISA recommend several proactive measures to mitigate the risk posed by Kali365 and similar token-based attacks:

  • Where feasible, restrict or entirely disable device code flow authentication within your organization’s Microsoft 365 environment.
  • Implement robust conditional access policies to prevent unauthorized use of device code authentication.
  • Before applying any restrictions, conduct a thorough audit of existing device code flow dependencies to avoid service disruptions.
  • Block authentication transfers between different devices to limit potential lateral movement.
  • Maintain dedicated emergency access accounts to ensure administrative access in the event of a lockout.
  • Organizations should actively monitor for any unusual sign-in activities or suspicious token usage patterns.

Victims of Kali365-related attacks are strongly urged to report incidents to the FBI’s Internet Crime Complaint Center (IC3) at www.ic3.gov. Essential information to include in the report comprises:

  • Complete phishing email samples, including full headers and content.
  • Details of suspicious login attempts, such as IP addresses, timestamps, and geographic locations.
  • Information regarding any unauthorized devices or active sessions identified.

The emergence of platforms like Kali365 underscores a significant evolution in phishing tactics, moving towards token-based attacks that bypass traditional defenses. This trend reinforces the critical need for organizations to implement stronger identity and access controls.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

CISA Warns of Critical Trend Micro Apex One RCE Vulnerability Exploated in Attacks

Next Post

macOS Malware Hides in Nested Folders to Evade Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us