Executive Summary
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service platform that enables attackers to hijack Microsoft 365 accounts by exploiting the OAuth device code authentication flow. This method allows cybercriminals to bypass multi-factor authentication (MFA) by capturing access and refresh tokens, granting persistent access to services like Outlook, Teams, and OneDrive without requiring user credentials. The attack typically involves phishing emails that direct victims to enter a device code on a legitimate Microsoft login page, unknowingly authorizing the attacker’s device. (ic3.gov)
The emergence of Kali365 underscores a significant shift in phishing tactics, highlighting the vulnerabilities in current authentication processes. As attackers increasingly adopt such sophisticated methods, organizations must reassess and strengthen their security protocols to mitigate the risks associated with token-based authentication exploits.
Why This Matters Now
The rise of Phishing-as-a-Service platforms like Kali365 demonstrates the evolving sophistication of cyber threats, emphasizing the need for organizations to enhance their security measures against advanced phishing techniques that can bypass traditional defenses.
Attack Path Analysis
The Kali365 phishing kit initiates the attack by presenting victims with a page impersonating trusted services like SharePoint, leading them to Microsoft's legitimate device login portal where they enter an attacker-provided code. This grants attackers access and refresh tokens, allowing persistent access to Microsoft 365 services. With these tokens, attackers can escalate privileges within the compromised environment. They then move laterally across the network, accessing additional resources and services. The attackers establish command and control channels to maintain communication and control over the compromised systems. Subsequently, they exfiltrate sensitive data, including emails and documents, to external servers. Finally, the attackers may disrupt operations, commit financial fraud, or cause reputational damage to the organization.
Kill Chain Progression
Initial Compromise
Description
Victims are lured to a phishing page impersonating trusted services like SharePoint, leading them to Microsoft's legitimate device login portal where they enter an attacker-provided code.
MITRE ATT&CK® Techniques
Spearphishing Link
Valid Accounts
Application Access Token
Email Collection
Data from Cloud Storage
Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for identifying and responding to security vulnerabilities are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Kali365's Microsoft authentication weaponization enables business email compromise and payment fraud, directly threatening banking operations and regulatory compliance requirements.
Health Care / Life Sciences
Device code phishing attacks compromise Microsoft 365 access to patient data and healthcare systems, violating HIPAA compliance and exposing sensitive medical information.
Government Administration
OAuth token abuse through legitimate Microsoft portals creates persistent access to classified communications and government cloud resources, enabling espionage activities.
Information Technology/IT
IT organizations face dual exposure as both targets and service providers, with compromised Microsoft 365 access potentially affecting multiple client environments simultaneously.
Sources
- Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Riskhttps://thehackernews.com/2026/08/kali365-weaponizes-microsoft.htmlVerified
- Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokenshttps://www.ic3.gov/PSA/2026/PSA260521?pubDate=20260525Verified
- FBI Warns: ‘Kali365’ Phishing Service Targets Microsoft 365 Accountshttps://www.techrepublic.com/article/fbi-warns-kali365-phishing-service-targets-microsoft-365-accounts/Verified
- Kali365 phishing kit bypasses MFA and steals Microsoft loginshttps://www.malwarebytes.com/blog/scams/2026/05/kali365-phishing-kit-bypasses-mfa-and-steals-microsoft-loginsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network segmentation and traffic control, it may not directly prevent initial phishing attacks. However, by limiting unauthorized access paths, it could reduce the overall attack surface.
Control: Zero Trust Segmentation
Mitigation: By implementing Zero Trust Segmentation, Aviatrix CNSF would likely limit the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: Aviatrix CNSF would likely constrain lateral movement by enforcing east-west traffic security, thereby limiting the attacker's ability to access additional resources and services.
Control: Multicloud Visibility & Control
Mitigation: With multicloud visibility and control, Aviatrix CNSF would likely detect and limit unauthorized command and control channels, reducing the attacker's ability to maintain control over compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix CNSF would likely limit data exfiltration by enforcing egress security policies, thereby restricting unauthorized outbound data transfers.
By implementing Aviatrix CNSF, the potential impact of such attacks would likely be reduced, as the attacker's ability to disrupt operations or exfiltrate sensitive data would be constrained.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- Cloud Storage
- Collaboration Platforms
Estimated downtime: 7 days
Estimated loss: $500,000
Corporate emails, internal documents, customer information, confidential business data
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic, preventing unauthorized access between workloads.
- • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights into cloud environments and detect anomalous activities.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration to unauthorized destinations.
- • Adopt Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors in real-time.



