FBI warns of Kali phishing scam hitting Microsoft OAuth tokens — warns 'Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures'

https://cdn.mos.cms.futurecdn.net/CT482eMSRL8PagRtuBVYNd-2000-80.jpeg
  • FBI flags Kali365, a phishing kit sold on Telegram which steals Microsoft 365 OAuth tokens and bypasses MFA
  • Victims are tricked into entering device codes on legitimate Microsoft pages, unknowingly authorizing attacker access to Outlook, Teams, and OneDrive
  • Mitigation steps include restricting device code flow, enforcing conditional access policies, auditing usage, and blocking authentication transfer policies

The FBI has warned of a new phishing kit which “lowers the barrier of entry” and allows even low-skilled malicious actors an easy way to compromise people’s Microsoft 365 accounts.

In a Public Service Announcement (PSA), Microsoft said that a new phishing kit, called Kali365, started making rounds on Telegram in April 2026. It is advertised as a simple way to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) without intercepting the user’s credentials.

“Through the Kali365 platform subscription, cyber threat actors can capture "OAuth" tokens and gain persistent access to targeted...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more