HomeBusinessThe FBI Has Warned That A New Phishing-As-A-Service Platform Called Kali365 Is...

The FBI Has Warned That A New Phishing-As-A-Service Platform Called Kali365 Is Hijacking Microsoft 365 OAuth Tokens And Bypassing Multi-Factor Authentication Without Ever Touching The Victim’s Password

Sold On Telegram, AI-Powered, Detected In April And Live At Scale By May: Kali365 Lowers The Skill Floor For Compromising Corporate Microsoft 365 Environments To Almost Zero

According to Infosecurity Magazine, the FBI issued an advisory on May 21 warning that a phishing-as-a-service platform called Kali365 is being distributed in the wild, primarily via Telegram. First detected in April 2026, the kit provides cybercriminals access to AI-generated phishing lures, automated campaign templates, and real-time tracking dashboards.

The attack chain is what makes it dangerous. The attacker sends a phishing email impersonating a trusted cloud service containing a device code. The victim navigates to the genuine Microsoft verification page and enters the code unknowingly authorising the attacker’s device to access their account. The attacker captures the OAuth access and refresh tokens, granting persistent access to Outlook, Teams, and OneDrive without ever needing the password or completing an MFA challenge.

This is a structural shift. Kali365 democratises a sophisticated technique that previously required nation-state skill. The FBI recommends restricting device code flow, deploying conditional access policies, and blocking authentication transfer policies. Every enterprise IT team should be acting on this advisory now.

To check out our previous coverage on cybersecurity threats and corporate defence, read our articles here.

RELATED ARTICLES

Most Popular