Executive Summary
In April 2026, a new Phishing-as-a-Service (PhaaS) platform named Kali365 emerged, enabling cybercriminals to hijack Microsoft 365 accounts by exploiting the OAuth device code flow. This method allows attackers to bypass multi-factor authentication (MFA) by tricking users into entering device codes on legitimate Microsoft verification pages, thereby granting unauthorized access to services like Outlook, OneDrive, and Teams. The FBI issued a public service announcement in May 2026, highlighting the widespread distribution of Kali365 via Telegram and its use in numerous attacks across various sectors, including manufacturing, education, government, financial services, and healthcare. (ic3.gov)
The significance of this incident lies in its demonstration of how attackers can circumvent traditional security measures, such as MFA, by exploiting legitimate authentication processes. The accessibility of Kali365 through subscription services lowers the barrier for less-skilled attackers to conduct sophisticated phishing campaigns, posing a substantial threat to organizations relying on Microsoft 365. (ic3.gov)
Why This Matters Now
The emergence of Kali365 underscores the evolving sophistication of phishing attacks, particularly those that can bypass multi-factor authentication by exploiting legitimate processes. Organizations must reassess their security protocols to address these advanced threats and implement additional safeguards beyond traditional MFA to protect sensitive data and systems.
Attack Path Analysis
The attack began with a phishing email impersonating a trusted cloud service, leading the victim to enter a device code on a legitimate Microsoft verification page. This granted the attacker OAuth tokens, allowing unauthorized access to the victim's Microsoft 365 account. With these tokens, the attacker escalated privileges to access services like Outlook, Teams, and OneDrive. The attacker then moved laterally within the cloud environment, accessing additional resources and data. Command and control were maintained through persistent access via the stolen OAuth tokens. Sensitive data was exfiltrated from the compromised services. Finally, the attacker impacted the organization by disrupting services and potentially deploying ransomware.
Kill Chain Progression
Initial Compromise
Description
The attacker sent a phishing email impersonating a trusted cloud service, prompting the victim to enter a device code on a legitimate Microsoft verification page, thereby granting the attacker OAuth tokens.
MITRE ATT&CK® Techniques
Application Layer Protocol: Web Protocols
Indicator Removal: Clear Persistence
Masquerading: Masquerade File Type
Command and Scripting Interpreter: Unix Shell
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for detecting and responding to failures are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector threats targeting encrypted traffic and zero trust controls pose severe risks to payment processing, customer data protection, and regulatory compliance requirements.
Health Care / Life Sciences
ClearFake and Kali365 threats combined with egress security gaps threaten patient data integrity, HIPAA compliance, and critical healthcare system availability.
Information Technology/IT
East-west traffic vulnerabilities and Kubernetes security weaknesses expose IT infrastructure to lateral movement attacks and shadow AI deployment risks.
Telecommunications
Salt Typhoon-related encrypted traffic threats and multicloud visibility gaps create significant risks to network infrastructure and customer communication security.
Sources
- Intelligence Insights: June 2026https://redcanary.com/blog/threat-intelligence/intelligence-insights-june-2026/Verified
- Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokenshttps://www.ic3.gov/PSA/2026/PSA260521Verified
- Kali365 phishing kit bypasses MFA and steals Microsoft loginshttps://www.malwarebytes.com/blog/scams/2026/05/kali365-phishing-kit-bypasses-mfa-and-steals-microsoft-loginsVerified
- Meet Kali365 - the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authenticationhttps://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authenticationVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial credential compromise, it could limit the attacker's subsequent access within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by enforcing strict access controls based on identity and workload segmentation.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could constrain the attacker's lateral movement by enforcing strict segmentation and monitoring of internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to maintain command and control by providing comprehensive monitoring and control over cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit data exfiltration by enforcing strict egress policies and monitoring outbound traffic.
Aviatrix Zero Trust CNSF could limit the attacker's ability to disrupt services and deploy ransomware by enforcing strict segmentation and access controls.
Impact at a Glance
Affected Business Functions
- Email Communication
- File Storage and Sharing
- Collaboration Platforms
Estimated downtime: 7 days
Estimated loss: $50,000
Unauthorized access to sensitive emails, confidential documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the cloud environment.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect anomalous interactions and repeated malformed requests indicative of command and control activities.
- • Apply Threat Detection & Anomaly Response mechanisms to identify and respond to covert tools and unauthorized remote access.
- • Enforce Inline IPS (Suricata) to inspect traffic for known exploit patterns and malicious payloads, blocking them before they reach critical systems.



