FBI Warns Kali365 Phishing Attacks Steal Microsoft 365 Credentials, Bypass MFA
Key Takeaways The FBI has issued a warning about Kali365, a new Phishing-as-a-Service (PhaaS) platform. Kali365 specifically targets Microsoft 365 users to steal OAuth tokens, enabling attackers to...
Key Takeaways
- The FBI has issued a warning about Kali365, a new Phishing-as-a-Service (PhaaS) platform.
- Kali365 specifically targets Microsoft 365 users to steal OAuth tokens, enabling attackers to bypass multi-factor authentication (MFA).
- This platform leverages Microsoft’s legitimate device code authentication flow, making detection challenging.
- Attackers gain persistent access to email, files, and communications without needing traditional credentials.
The Federal Bureau of Investigation (FBI) has released a public cybersecurity alert concerning Kali365, a sophisticated Phishing-as-a-Service (PhaaS) platform. This emerging threat is designed to compromise Microsoft 365 user accounts by illicitly acquiring access tokens, effectively circumventing multi-factor authentication (MFA) protocols.
Table Of Content
Kali365 is primarily disseminated through Telegram channels, providing a low-barrier entry point for threat actors. Subscribers to the service can initiate phishing campaigns with minimal technical expertise.
A significant departure from conventional credential-harvesting methods, Kali365 focuses on capturing OAuth tokens. This mechanism grants attackers enduring access to Microsoft 365 accounts without requiring the user’s username, password, or even their MFA codes.
The platform is equipped with several features that streamline the attack process for cybercriminals:
- AI-driven generation of convincing phishing email templates that mimic legitimate services.
- Automated tools for deploying and managing phishing campaigns.
- Dashboards offering real-time tracking of victim engagement.
- Integrated mechanisms for capturing OAuth tokens.
This comprehensive toolkit empowers even less-skilled attackers to execute large-scale, sophisticated phishing operations.
Kali365 PhaaS Targets Microsoft 365
The Kali365 attack methodology exploits Microsoft’s legitimate device code authentication flow to trick users into inadvertently authorizing malicious access. The process unfolds in several stages:
- Lure: Victims receive deceptive phishing emails, often appearing to originate from Microsoft or trusted document-sharing services. These emails contain a device code and instructions prompting the user to take action.
- Authorization: The user is then directed to an authentic Microsoft verification page, where they are instructed to input the provided device code.
- Token Theft: By entering the code, the user unknowingly grants authorization for the attacker’s session, allowing the attacker to intercept OAuth access and refresh tokens.
- Persistence: With these tokens, attackers can then access critical Microsoft 365 services such as Outlook, Teams, and OneDrive without needing to re-authenticate or trigger MFA.
This technique poses a significant risk because it weaponizes legitimate authentication workflows, making such intrusions considerably harder to detect through traditional security measures.
Today the FBI released a #PSA warning the public about Kali365—an emerging Phishing-as-a-Service (PhaaS) platform. Kali365, first seen in April 2026, enables cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without… pic.twitter.com/AalckpLVHG
— FBI Cyber Division (@FBICyberDiv) May 21, 2026
Identified under Alert Number I-052126-PSA and initially observed in April 2026, the Kali365 platform is rapidly gaining traction among cybercriminals due to its user-friendly interface and advanced capabilities.
Once attackers successfully gain access, they can perform a variety of malicious actions:
- Read and exfiltrate sensitive emails.
- Access and download confidential files stored in OneDrive.
- Monitor and intercept communications via Microsoft Teams.
- Maintain long-term persistence within the compromised environment using stolen refresh tokens.
Since this method avoids direct credential theft, it often bypasses conventional security alerts, potentially increasing the attacker’s dwell time within the victim’s network.
What You Should Do
The FBI and CISA recommend several proactive measures to mitigate the risk posed by Kali365 and similar token-based attacks:
- Where feasible, restrict or entirely disable device code flow authentication within your organization’s Microsoft 365 environment.
- Implement robust conditional access policies to prevent unauthorized use of device code authentication.
- Before applying any restrictions, conduct a thorough audit of existing device code flow dependencies to avoid service disruptions.
- Block authentication transfers between different devices to limit potential lateral movement.
- Maintain dedicated emergency access accounts to ensure administrative access in the event of a lockout.
- Organizations should actively monitor for any unusual sign-in activities or suspicious token usage patterns.
Victims of Kali365-related attacks are strongly urged to report incidents to the FBI’s Internet Crime Complaint Center (IC3) at www.ic3.gov. Essential information to include in the report comprises:
- Complete phishing email samples, including full headers and content.
- Details of suspicious login attempts, such as IP addresses, timestamps, and geographic locations.
- Information regarding any unauthorized devices or active sessions identified.
The emergence of platforms like Kali365 underscores a significant evolution in phishing tactics, moving towards token-based attacks that bypass traditional defenses. This trend reinforces the critical need for organizations to implement stronger identity and access controls.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.