logo

FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens

ID: 37ee9e55-3ef3-527a-b40a-52bbcac0c5df

STIX ID: report--37ee9e55-3ef3-527a-b40a-52bbcac0c5df

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

...
...

Kali365 is a newly observed phishing-as-a-service (PhaaS) platform, first detected in April 2026 and distributed primarily via Telegram, that supplies AI-generated phishing lures, automated campaign templates, and dashboards for targeted tracking. Attackers use device-code phishing to capture Microsoft 365 OAuth access and refresh tokens—bypassing MFA and achieving persistent access to services such as Outlook, Teams, and OneDrive; the FBI advisory describes the attack chain and recommends restricting device code flow and implementing conditional access policies as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.