FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
ID: 08fe1f8d-5214-5aae-9d9f-aa8fa5c18996
STIX ID: report--08fe1f8d-5214-5aae-9d9f-aa8fa5c18996
Feed Name: The Record from Recorded Future News
Cybercriminals are using Kali365, a Telegram-distributed Phishing-as-a-Service, to capture OAuth access and refresh tokens and gain persistent access to Microsoft 365 accounts—bypassing MFA and enabling mailbox takeover, lateral phishing, and administrative actions. The FBI and multiple security firms reported hundreds of attacks since April 2026; Kali365 provides turnkey phishing lures, templates, tracking dashboards, token storage and resale, illustrating the professionalization and commoditization of these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
