FBI warns about Kali365 phishing service hijacking Microsoft 365 OAuth tokens and gaining access to accounts without passwords.

The FBI recently issued a warning about Kali365, a phishing-as-a-service platform that exploits Microsoft 365’s OAuth authentication. This new threat enables attackers to bypass multi-factor authentication using AI-generated phishing lures.

Sources:
ForbesInfosecurity Magazine+1
Trending 10m ago
Tab background
Sources: ForbesInfosecurity Magazine
The FBI has issued a warning regarding the threat posed by Kali365, a phishing-as-a-service (PhaaS) platform that emerged in April 2026. This service employs advanced AI tools to streamline phishing campaigns, enabling low-skilled cybercriminals to bypass multi-factor authentication (MFA) and obtain Microsoft 365 OAuth tokens.

Kali365 allows attackers to access Microsoft 365 services like Outlook, Teams, and OneDrive without needing passwords. Instead, victims unknowingly authorize the attackers’ devices by entering a device code sent via phishing emails, which Kali365 generates. Once authorization occurs, attackers capture OAuth access and refresh tokens, establishing persistence in compromised accounts.

The FBI warns that these techniques markedly lower entry barriers for cybercriminals. Kali365 provides access to AI-generated phishing lures and real-time tracking dashboards, making sophisticated phishing methods available even to those lacking technical expertise.

To combat this threat, the FBI recommends organizations implement conditional access policies to restrict or block device code authentication flows and to audit existing device code usage.

The rise of sophisticated phishing tools like Kali365 poses a significant risk to organizations, emphasizing the need for stringent security measures in the Microsoft 365 environment.
Sources: Forbes
The FBI has issued a warning regarding Kali365, an AI-driven phishing service that enables cyber attackers to hijack Microsoft 365 OAuth tokens, bypassing multi-factor authentication and gaining unauthorized access to user accounts without needing passwords, potentially affecting organizations globally.
Section 1 background
The Headline

FBI warns about Kali365 phishing kit

Key Facts
  • FBI issues a warning on May 21 about a new AI-powered attack using the Kali365 phishing kit that enables threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication protocols without intercepting user credentials.Forbes
  • Kali365 is a phishing-as-a-service platform that was first discovered in April 2026 and is distributed through Telegram channels to assist cybercriminals in compromising Microsoft 365 accounts.1
  • The service allows attackers to capture OAuth tokens, granting them access to various Microsoft 365 services such as Outlook, Teams, and OneDrive without requiring a password or additional MFA challenges.Forbes
  • Kali365 significantly lowers the barrier of entry for less-technical attackers by providing access to AI-generated phishing lures, automated campaign templates, and token capture capabilities.Forbes
Section 2 background
Background Context

Background on Kali365 operations

Key Facts
  • In typical attacks, victims receive phishing emails that impersonate trusted cloud services, leading them to the legitimate Microsoft page where they unknowingly authorize attackers by pasting in a device code.Infosecurity Magazine
  • With captured tokens, attackers gain persistent access to the victim's Microsoft 365 account, which can lead to further data theft across various services.Infosecurity Magazine
  • Researchers observed widespread Kali365 activity targeting organizations, showcasing its effectiveness and reach in compromising Microsoft 365 environments using targeted phishing strategies.
Article not found
CuriousCats.ai

Article

Source Citations