Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitLab Suspends Nightmare-Eclipse After GitHub Ban
May 27, 2026
CERT-In: Patch Critical Vulnerabilities in Systems Within
May 27, 2026
BIND 9 Flaws Expose Servers & Resolvers to Software Vulnerabilities
May 27, 2026
Home/CyberSecurity News/FBI Warns: Kali365 Attacks Microsoft Attacking Users
CyberSecurity News

FBI Warns: Kali365 Attacks Microsoft Attacking Users

The FBI has issued a new cybersecurity warning regarding Kali365, a rapidly emerging phishing-as-a-service (PhaaS) platform. This platform actively targets Microsoft 365 users, aiming to steal access...

Emy Elsamnoudy
Emy Elsamnoudy
May 22, 2026 3 Min Read
16 0

The FBI has issued a new cybersecurity warning regarding Kali365, a rapidly emerging phishing-as-a-service (PhaaS) platform. This platform actively targets Microsoft 365 users, aiming to steal access tokens and bypass multi-factor authentication (MFA).

Kali365 is being distributed primarily through Telegram channels, where threat actors can subscribe to the service and launch phishing campaigns with minimal technical knowledge.

Unlike traditional credential-harvesting attacks, Kali365 focuses on capturing OAuth tokens, enabling attackers to gain persistent access to Microsoft 365 accounts without requiring usernames, passwords, or MFA codes.

The platform includes several built-in features that lower the barrier to entry for attackers:

  • AI-generated phishing email templates impersonating trusted services.
  • Automated campaign deployment tools.
  • Real-time dashboards to track victims.
  • OAuth token capture mechanisms.

This combination enables even low-skilled attackers to execute sophisticated phishing campaigns at scale.

Kali365 PhaaS Targets Microsoft 365

The Kali365 attack leverages Microsoft’s legitimate device code authentication flow to trick users into authorizing malicious access.

  • Lure: Victims receive phishing emails that appear to be from Microsoft or document-sharing platforms. These emails include a device code and instructions.
  • Authorization: The victim is directed to a legitimate Microsoft verification page and asked to enter the provided code.
  • Token Theft: By entering the code, the user unknowingly authorizes the attacker’s session, allowing them to capture OAuth access and refresh tokens.
  • Persistence: Attackers can then access services like Outlook, Teams, and OneDrive without triggering MFA again.

This technique is particularly dangerous because it exploits legitimate authentication workflows, making detection more difficult.

Today the FBI released a #PSA warning the public about Kali365—an emerging Phishing-as-a-Service (PhaaS) platform. Kali365, first seen in April 2026, enables cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without… pic.twitter.com/AalckpLVHG

— FBI Cyber Division (@FBICyberDiv) May 21, 2026

Tracked under Alert Number I-052126-PSA and first observed in April 2026, the platform is gaining traction among cybercriminals due to its ease of use and advanced capabilities.

Once access is gained, attackers can:

  • Read and exfiltrate emails.
  • Access sensitive files stored in OneDrive.
  • Monitor communications via Teams.
  • Maintain long-term persistence using refresh tokens.

Because credentials are not directly stolen, traditional security alerts may not be triggered, thereby increasing dwell time.

Mitigation Recommendations

The FBI and CISA recommend several defensive measures to reduce exposure:

  • Restrict or turn off device code flow authentication where possible.
  • Implement conditional access policies to block unauthorized device code usage.
  • Audit existing device code flow dependencies before applying restrictions.
  • Block authentication transfer between devices.
  • Maintain emergency access accounts to prevent lockouts.

Organizations should also monitor for unusual sign-ins and token usage patterns.

Victims of Kali365-related attacks are encouraged to report incidents to the FBI’s Internet Crime Complaint Center (IC3) at www.ic3.gov. Key information to include:

  • Phishing email samples (headers and content).
  • Suspicious login details (IP, time, location).
  • Unauthorized devices or active sessions.

As phishing techniques continue to evolve, the Kali365 platform highlights a growing shift toward token-based attacks that bypass traditional defenses, reinforcing the need for stronger identity and access controls.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

CISA Warns: Trend Micro Apex One Vulner Vulnerability Exploited

Next Post

Hackers Evade Scanners with Malware in Nested macOS Fold

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Angular Language Service Flaws Enable Remote Code Execution
May 26, 2026
Quasar Linux RAT Targets Developers via Fileless eBPF
May 26, 2026
China-Linked Hackers Target SEA Edge Routers with Southeast Asian
May 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us