The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA).
Kali365 is being distributed primarily through Telegram channels, where threat actors can subscribe to the service and launch phishing campaigns with minimal technical knowledge.
Unlike traditional credential-harvesting attacks, Kali365 focuses on capturing OAuth tokens, enabling attackers to gain persistent access to Microsoft 365 accounts without requiring usernames, passwords, or MFA codes.
The platform includes several built-in features that lower the barrier to entry for attackers:
This combination enables even low-skilled attackers to execute sophisticated phishing campaigns at scale.
The Kali365 attack leverages Microsoft’s legitimate device code authentication flow to trick users into authorizing malicious access.
This technique is particularly dangerous because it exploits legitimate authentication workflows, making detection more difficult.
Tracked under Alert Number I-052126-PSA and first observed in April 2026, the platform is gaining traction among cybercriminals due to its ease of use and advanced capabilities.
Once access is gained, attackers can:
Because credentials are not directly stolen, traditional security alerts may not be triggered, thereby increasing dwell time.
The FBI and CISA recommend several defensive measures to reduce exposure:
Organizations should also monitor for unusual sign-ins and token usage patterns.
Victims of Kali365-related attacks are encouraged to report incidents to the FBI’s Internet Crime Complaint Center (IC3) at www.ic3.gov. Key information to include:
As phishing techniques continue to evolve, the Kali365 platform highlights a growing shift toward token-based attacks that bypass traditional defenses, reinforcing the need for stronger identity and access controls.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
The post FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA appeared first on Cyber Security News.
The post Torneos Upgrades Multichannel Playout With Imagine’s Versio appeared first on TV News Check.
The post Fuse Media Taps iSpot As Official Measurement Provider For FAST & CTV Inventory…
The post Ross Video to Invest C$122.5 Million To Expand Manufacturing & R&D appeared first…
The post NAB Show Makes 200+ Sessions Available On Demand appeared first on TV News…
The post Apple TV To Capture MLS Game Entirely On iPhone 17 Pro appeared first…
Grass Valley entered into a three-year enterprise agreement with Singapore-based Phoenix Broadcast Solutions as the…
This website uses cookies.