logo

FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks

ID: 08fe1f8d-5214-5aae-9d9f-aa8fa5c18996

STIX ID: report--08fe1f8d-5214-5aae-9d9f-aa8fa5c18996

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

...
...

Cybercriminals are using Kali365, a Telegram-distributed Phishing-as-a-Service, to capture OAuth access and refresh tokens and gain persistent access to Microsoft 365 accounts—bypassing MFA and enabling mailbox takeover, lateral phishing, and administrative actions. The FBI and multiple security firms reported hundreds of attacks since April 2026; Kali365 provides turnkey phishing lures, templates, tracking dashboards, token storage and resale, illustrating the professionalization and commoditization of these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.