HomeSecurityFBI: Kali365 phishing service targets Microsoft 365 accounts

FBI: Kali365 phishing service targets Microsoft 365 accounts

The FBI has issued a warning about the Kali365 platform , a dangerous phishing-as-a-service ( PhaaS ) service that targets Microsoft 365 accounts using advanced multi-factor authentication ( MFA ) bypass techniques. The service exploits Microsoft ’s legitimate OAuth device code authentication system to steal session tokens and gain access to corporate accounts without having to steal passwords.

Kali365

According to the announcement , Kali365 first appeared in April 2026 and is distributed via Telegram to criminals looking for easy ways to compromise Microsoft 365. The platform uses the device code phishing, an increasingly popular method that exploits Microsoft's legitimate OAuth 2.0 Device Authorization to gain access to Microsoft Entra and Microsoft 365.

See also: Apple competes with Google Workspace and Microsoft 365 with new email service

This authentication method was originally created to allow devices with limited input capabilities, such as smart TVs, conference room systems, streaming devices, printers, and IoT devices, to authenticate through another device using a short code on Microsoft (http://microsoft.com/devicelogin). The attacks work like this: crooks initiate the device authorization process to generate a code, then trick victims into entering it on the Microsoft login page through phishing and social engineering.

Advanced Kali365 features and technical details

The FBI warns that Kali365 allows even hackers with minimal knowledge to gain access to advanced phishing capabilities, including AI-generated phishing lures, automated campaign templates, real-time victim monitoring dashboards, and token logging functionality. Once the victim enters the password and completes MFA, Microsoft issues an OAuth access token that grants the attacker full access to their account without having to solve any MFA challenges.

FBI: Kali365 phishing service targets Microsoft 365 accounts

Security researchers from Arctic Wolf reported Kali365 activity in April after observing a widespread campaign targeting organizations worldwide. The researchers said the campaigns primarily targeted Microsoft 365, using phishing emails that directed victims to Microsoft’s device code login portal, where they unwittingly authorized attackers to gain access to their accounts. Hackers gain full access to all applications that a user would normally access through their single-sign-on account, including Microsoft 365, Salesforce , or any other cloud SaaS platform.

See also: Microsoft discontinues malware code-signing service

Researchers discovered that Kali365 operates as a business, with administrators managing product development, resellers promoting the service to other threat actors, and partners conducting phishing attacks. The platform offers two distinct attack vectors, the first being device code phishing and the second being an adversary-in-the-middle ( AitM ) operation called “Cookie Link . ” Cookie Link funnels victims through infrastructure controlled by attackers and captures authenticated browser sessions, session cookies, and tokens after targets log in and solve MFA challenges.

Protection recommendations

The FBI recommends that companies limit or completely block device code authentication flows by using Conditional Access policies where possible. They should also audit existing device code usage and block authentication transfer policies that allow authentication sessions to move between devices. The agency also urged affected organizations to report incidents to the Internet Crime Complaint Center and to keep a record of phishing emails, suspicious login information, and unauthorized device registrations.

FBI: Kali365 phishing service targets Microsoft 365 accounts

Organizations should also enforce conditional access and monitor for unusual token issuance, unusual logins, and unknown active sessions, as the attack can bypass MFA once a valid token is obtained. Additionally, teams should educate users not to enter verification codes unless they have intentionally initiated a Microsoft login, as the attack relies on social engineering rather than technical exploits.

See also: Microsoft reveals Storm-2949 attack on Azure Cloud and Microsoft 365

According to BleepingComputer, this warning is part of a broader increase in device code phishing attacks that exploit legitimate identification processes.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS