logo

Microsoft 365 users targeted by new phishing threat that bypasses MFA

ID: 4fc6cbfc-06c9-55d1-b57d-30f67adc375a

STIX ID: report--4fc6cbfc-06c9-55d1-b57d-30f67adc375a

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Sinisa Markovic

...
...

The FBI warns of Kali365, a Telegram-distributed Phishing-as-a-Service first observed in April 2026 that enables attackers to perform device code phishing against Microsoft 365, capturing OAuth access and refresh tokens to bypass MFA and maintain access to Outlook, Teams, OneDrive and other services; the report also notes a related service, EvilTokens, and provides defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.