Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

FBI Warns Kali365 Phishing Kit Is Stealing Microsoft OAuth Tokens at Scale

The FBI says the service uses device-code phishing and adversary-in-the-middle tactics to bypass multi-factor authentication and steal session data.

  • The FBI issued a public service announcement warning about Kali365, a phishing-as-a-service platform on Telegram targeting M365 users to steal OAuth tokens at alarming rates.
  • Researchers identified three distinct subscription tiers for the platform, with The Admin Tier reserved for developers and The Agent Tier enabling resellers to manage branded panels.
  • Kali365 enables attackers to impersonate "trusted cloud productivity and document-sharing services" like Adobe Acrobat Sign, DocuSign, and SharePoint, according to Arctic Wolf. The platform uses AitM capabilities to proxy browser sessions and bypass Microsoft MFA.
  • Tanmay Ganacharya, VP of security research at Microsoft, told The Register, "We continue to observe high-volume activity," with campaigns targeting hundreds of organizations using unique payloads that challenge defenders' detection efforts.
  • Both Arctic Wolf and the FBI recommend organizations implement conditional access policies to block device code flow and authentication transfer policies on PCs and phones to mitigate compromise risks.
Insights by Ground AI

12 Articles

Stealing a password? It almost became an accessory. The FBI has launched an alert on Kali365, a hack kit that enters a company's Microsoft 365 accounts without ever needing the password, nor the famous double authentication code. The protection that many imagine is no longer of great use here. Alas. Kali365 is not a classic virus. This is called a rental phishing kit: a turnkey service, sold a little like a subscription to a software, except tha…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT Security News - cybersecurity, infosecurity news broke the news on Friday, May 22, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal