Full Breakdown
Kali365 Phishing-as-a-Service Threat Targets Microsoft 365 Accounts
5/26/2026, 12:19:55 PM
Core Threat Overview
In a public service announcement dated May 21, 2026, the FBI warned that a new phishing-as-a-service (PhaaS) platform called Kali365 is being sold primarily on Telegram. First detected in April 2026, the kit enables attackers to obtain Microsoft 365 OAuth access and refresh tokens, allowing them to bypass multi-factor authentication (MFA) without ever intercepting user passwords. By exploiting Microsoft’s device-code authentication flow, the service lets low-skill actors launch automated campaigns that impersonate trusted cloud-productivity and document-sharing services.
Background: Device-Code Flow and OAuth Token Theft
Microsoft’s device-code workflow was designed for devices with limited input (e.g., smart TVs). When a user enters a code on a legitimate Microsoft verification page, the platform issues an OAuth token that grants ongoing access to Outlook, Teams, OneDrive, and other services. Security researchers note that token theft is increasingly attractive because tokens maintain authenticated sessions across services and remain valid until revoked, making them more valuable than static passwords.
Attack Chain and Tactics
1. Phishing Email – The attacker sends an email that mimics a trusted Microsoft-linked service, using one of eight fixed templates (e.g., “SharePoint – Document Shared” or “Teams – New Message”).
2. Device-Code Prompt – The email contains a device code and instructions to visit a genuine Microsoft verification page.
3. User Authorization – The victim enters the code, unintentionally authorizing the attacker’s device.
4. Token Capture – The attacker captures the OAuth access and refresh tokens, securing persistent access to the victim’s Microsoft 365 environment.
5. Post-Compromise Activity – With tokens, the adversary can read Outlook mail, join Teams chats, retrieve OneDrive files, and even register new devices, all without triggering additional MFA challenges.
Mitigation Guidance from Authorities
The FBI’s advisory lists several defensive measures:
- Restrict or block device-code flow for most users, applying conditional-access policies with limited exceptions for essential business processes.
- Block authentication-transfer policies that allow credentials to move between computers and mobile devices.
- Audit existing device-code usage to identify legitimate dependencies before enforcement.
- Exclude emergency-access accounts from restrictions to avoid lockouts.
Microsoft’s own PSA echoes these steps and advises organizations to monitor authentication activity and follow the Cybersecurity and Infrastructure Security Agency’s phishing-mitigation guidance. Arctic Wolf researchers highlight the kit’s ease of use—AI-generated lures, automated dashboards, and a subscription price ranging from $10 to $1,000—underscoring the low barrier to entry for threat actors.
Criticism & Concerns from Security Researchers
Security analysts caution that the proliferation of token-theft kits like Kali365, EvilTokens, and Tycoon2FA expands the attack surface for cloud productivity platforms. The reliance on legitimate Microsoft pages makes detection difficult, and the rapid emergence of new device-code phishing tools each week suggests a growing ecosystem that could outpace current defensive controls.
Verbatim Quotes
- “Kali365 lowers the barrier of entry,” the bureau says, “providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.” — FBI, Public Service Announcement
- “Through the Kali365 platform subscription, cyber threat actors can capture "OAuth" tokens and gain persistent access to targeted individuals/entities' Microsoft 365 environments,” the FBI warned.” — FBI, PSA
- “The FBI says a new scam based on the Kali365 phishing-as-a-service platform can bypass multi-factor authentication (MFA) by tricking users into approving legitimate Microsoft logins.” — FBI, public statement
- “The FBI warned that Kali365 significantly lowers the barrier to entry for cybercrime operations by offering built-in phishing templates, AI-generated phishing lures, automated campaign tools, and real-time dashboards that track victims and stolen tokens.” — FBI, advisory
- “FBI Urges Victims to Report Incidents The FBI is urging anyone impacted by the Kali365 phishing campaign to report incidents through the Internet Crime Complaint Center (IC3).” — FBI, advisory
What’s Next
The FBI urges victims to submit evidence to the IC3 and recommends that organizations implement the outlined conditional-access policies promptly. Ongoing monitoring by Microsoft, CISA, and security firms will track the evolution of token-theft kits, while law-enforcement investigations aim to disrupt the Telegram distribution channels that fuel Kali365’s growth.
