Executive Summary
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to hijack Microsoft 365 access tokens by exploiting OAuth device code authorizations. Distributed primarily via Telegram, Kali365 allows attackers to bypass multi-factor authentication (MFA) without intercepting user credentials. This method grants persistent access to Microsoft 365 services, including Outlook, Teams, and OneDrive, facilitating data theft, fraud, extortion, and potential ransomware attacks. (ic3.gov)
The emergence of Kali365 underscores a significant shift in phishing tactics, with attackers increasingly leveraging device code phishing to circumvent traditional security measures. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving threats. (helpnetsecurity.com)
Why This Matters Now
The rapid proliferation of platforms like Kali365 demonstrates a growing sophistication in phishing attacks, emphasizing the necessity for organizations to implement advanced security measures and user training to counteract these evolving threats.
Attack Path Analysis
Attackers utilized the Kali365 phishing-as-a-service platform to send AI-generated phishing emails impersonating trusted services, leading victims to authorize malicious applications via legitimate Microsoft device code authorization pages. This granted attackers persistent access to victims' Microsoft 365 accounts without requiring credentials or multi-factor authentication, enabling them to escalate privileges, move laterally within the organization, establish command and control channels, exfiltrate sensitive data, and potentially disrupt operations through fraud, extortion, or ransomware attacks.
Kill Chain Progression
Initial Compromise
Description
Attackers sent AI-generated phishing emails impersonating trusted services, directing victims to enter a device code on a legitimate Microsoft authorization page, thereby granting access to malicious applications.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Cloud Accounts
Application Access Token
Web Protocols
Remote Email Collection
Exfiltration Over Web Service
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and security events are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value targets for Kali365 phishing-as-a-service attacks bypassing MFA, enabling OAuth token theft for fraud, data extortion, and regulatory compliance violations.
Health Care / Life Sciences
Critical HIPAA compliance risks from Microsoft 365 token capture enabling persistent access to protected health information for ransomware and data theft.
Government Administration
Significant national security implications from device-code phishing targeting government Microsoft 365 environments, enabling espionage and sensitive data exfiltration through bypassed authentication.
Information Technology/IT
Primary infrastructure targets where compromised Microsoft 365 tokens provide privileged access for lateral movement, affecting client networks and managed services delivery.
Sources
- FBI warns about fast-growing phishing kit targeting Microsoft 365 usershttps://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/Verified
- Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokenshttps://www.ic3.gov/PSA/2026/PSA260521Verified
- Microsoft 365 users targeted by new phishing threat that bypasses MFAhttps://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely reduce the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to gain initial access through phishing may be limited by enforcing strict identity-aware access controls.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may be constrained by limiting access to sensitive resources based on strict segmentation policies.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network may be limited by enforcing east-west traffic controls that restrict unauthorized internal communications.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may be constrained by providing comprehensive visibility and control over multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data may be limited by enforcing strict egress policies that control outbound data flows.
The overall impact of the attack may be reduced by limiting the attacker's ability to escalate privileges, move laterally, and exfiltrate data through comprehensive security controls.
Impact at a Glance
Affected Business Functions
- Email Communication
- Document Management
- Collaboration Tools
- Cloud Storage
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive corporate data, including emails, documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within Microsoft 365 services.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to unauthorized access and unusual activities promptly.
- • Utilize Multicloud Visibility & Control tools to monitor and manage access across cloud services, ensuring comprehensive oversight.
- • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration to unauthorized destinations.
- • Regularly audit and restrict OAuth application permissions to minimize the risk of unauthorized access through malicious applications.



