logo

FBI Warns of Kali365 Phishing-as-a-Service Platform After April Microsoft 365 Attacks

ID: f79c8fb5-4698-57d9-a446-d423be0f951f

STIX ID: report--f79c8fb5-4698-57d9-a446-d423be0f951f

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-05-24

Date Updated: 2026-05-24

Author: John Kevin Hao

...
...

The FBI and multiple security firms warned of Kali365, a Telegram-distributed phishing-as-a-service first seen in April that exploits Microsoft’s OAuth device code flow to capture access and refresh tokens for persistent Microsoft 365 account access; the platform offers branded, multi-language phishing lures, tiered pricing, and a desktop client, has been linked to hundreds of attacks enabling mailbox takeover, lateral phishing, and business-email-compromise, and defenders are advised to apply conditional access for managed devices, monitor device authorization events and inbox rules, and train staff on device-code phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.