đ° Full Story
The U.S. Federal Bureau of Investigation this week issued a public warning about Kali365, a rapidly growing phishing-as-a-service platform that harvests Microsoft 365 OAuth access and refresh tokens to bypass multi-factor authentication and gain persistent access to Outlook, Teams, OneDrive and other services.
First observed in April 2026 and proliferating on Telegram, Kali365 uses device-code phishing: victims are lured to paste a code into a legitimate Microsoft verification page, unintentionally authorising a malicious application.
Security firms including Proofpoint and Arctic Wolf report the toolkit offers AI-generated lures, campaign templates, tracking dashboards and token storage; affiliates can purchase access (reported pricing about $250/month or $2,000/year). Researchers have seen multiple near-identical device-code phishing platforms emerge since February 2026.
Stolen tokens can be shared among criminals and enable business email compromise, data theft, fraud, extortion and ransomware deployment.
The FBI and CISA recommend limiting or disabling device-code flows, applying strict conditional access and monitoring token use while preserving emergency access processes to avoid lockouts.







đŹ Commentary