FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens
ID: 37ee9e55-3ef3-527a-b40a-52bbcac0c5df
STIX ID: report--37ee9e55-3ef3-527a-b40a-52bbcac0c5df
Feed Name: Infosecurity Magazine (News)
Kali365 is a newly observed phishing-as-a-service (PhaaS) platform, first detected in April 2026 and distributed primarily via Telegram, that supplies AI-generated phishing lures, automated campaign templates, and dashboards for targeted tracking. Attackers use device-code phishing to capture Microsoft 365 OAuth access and refresh tokens—bypassing MFA and achieving persistent access to services such as Outlook, Teams, and OneDrive; the FBI advisory describes the attack chain and recommends restricting device code flow and implementing conditional access policies as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
