Executive Summary
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform that enables attackers to hijack Microsoft 365 accounts by stealing OAuth tokens, effectively bypassing multi-factor authentication (MFA). Distributed primarily via Telegram, Kali365 provides AI-generated phishing lures and automated campaign templates, allowing even low-skilled cybercriminals to gain unauthorized access to services like Outlook, Teams, and OneDrive without needing user credentials. (ic3.gov)
The emergence of Kali365 underscores a significant shift in phishing tactics, highlighting the increasing sophistication and accessibility of PhaaS platforms. This development emphasizes the urgent need for organizations to enhance their security measures beyond traditional MFA, as attackers continue to exploit legitimate authentication workflows to gain unauthorized access.
Why This Matters Now
The rapid proliferation of PhaaS platforms like Kali365 lowers the barrier for cybercriminals, enabling widespread attacks that can compromise sensitive data and disrupt business operations. Organizations must urgently reassess and strengthen their authentication and phishing detection mechanisms to mitigate this evolving threat landscape.
Attack Path Analysis
Attackers utilized the Kali365 phishing-as-a-service platform to send AI-generated phishing emails, tricking users into entering device codes on legitimate Microsoft verification pages. This granted attackers OAuth tokens, allowing them to bypass multi-factor authentication and gain persistent access to Microsoft 365 services. With these tokens, attackers escalated privileges within the compromised accounts, enabling further malicious activities. They then moved laterally across the organization's cloud environment, accessing additional resources and services. Established command and control channels allowed attackers to maintain control over compromised accounts and systems. Sensitive data was exfiltrated from Microsoft 365 services, including emails and files stored in OneDrive. The attack resulted in significant operational disruption and potential data breaches, impacting the organization's reputation and compliance standing.
Kill Chain Progression
Initial Compromise
Description
Attackers sent AI-generated phishing emails containing device codes, tricking users into entering these codes on legitimate Microsoft verification pages, thereby obtaining OAuth tokens.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Valid Accounts
Application Layer Protocol: Web Protocols
Application Layer Protocol: Web Protocols
Brute Force: Password Spraying
Modify Authentication Process: Multi-Factor Authentication
Valid Accounts: Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and network security are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Kali365's device code phishing bypasses MFA protections on AWS and Okta platforms, threatening OAuth token security and regulatory compliance requirements.
Information Technology/IT
Expanded phishing-as-a-service targeting Microsoft 365, AWS, and Okta creates significant risks for IT infrastructure and cloud service authentication mechanisms.
Government Administration
FBI-flagged Kali365's targeting of Russian state platforms and Western enterprises poses national security risks through compromised digital identity infrastructure.
Health Care / Life Sciences
Device code phishing attacks against cloud platforms threaten HIPAA compliance and patient data protection through compromised authentication and access controls.
Sources
- FBI-Flagged Phishing Kit Kali365 Expands Its Reachhttps://www.darkreading.com/cyber-risk/fbi-flagged-phishing-kit-kali365-expands-its-reachVerified
- From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Serviceshttps://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/Verified
- Recognize and Report Phishinghttps://www.cisa.gov/secure-our-world/recognize-and-report-phishingVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it embeds security directly into the cloud fabric, potentially limiting attackers' ability to move laterally and exfiltrate data within the cloud environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could potentially limit the impact of compromised credentials by restricting unauthorized access paths within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit attackers' ability to escalate privileges by enforcing strict access controls and segmenting network resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain lateral movement by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and disrupt command and control channels by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.
While Aviatrix CNSF cannot entirely prevent operational disruptions, it could likely reduce the scope of such incidents by limiting attackers' ability to access and exfiltrate sensitive data.
Impact at a Glance
Affected Business Functions
- Email Communications
- Cloud Storage Access
- Collaboration Platforms
- Identity and Access Management
Estimated downtime: 3 days
Estimated loss: $50,000
Unauthorized access to sensitive corporate emails, documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the cloud environment.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud activities and detect anomalous behaviors.
- • Apply Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities in real-time.
- • Enforce Cloud Native Security Fabric (CNSF) controls to provide distributed policy enforcement and real-time inspection across cloud services.



