The FBI issues a public warning about “Kali365,” a fast-spreading phishing-as-a-service platform used to compromise Microsoft 365 accounts. Multiple outlets report that the kit does not require attackers to steal users’ passwords. Instead, Kali365 abuses legitimate Microsoft authentication flows—particularly OAuth and related “device code” login mechanisms—to obtain session tokens and effectively take over accounts used for services such as Outlook, Teams, and OneDrive.
Bleeping Computer and TechRadar describe the approach as using device code phishing, allowing attackers to capture OAuth tokens and bypass multi-factor authentication protections. Other reports, including Inc. and Infosecurity Magazine, emphasize that the tool lowers the technical barrier for less-skilled criminals, enabling more widespread phishing campaigns. Dark Reading adds that while Kali365 initially targeted Microsoft 365, it is expanding to other platforms, including AWS and Okta, and relies on the same general device-code-based method.
The overall guidance reported across sources centers on the FBI’s warning that Microsoft 365 users face increasing phishing attempts designed to hijack authenticated sessions rather than simply trick victims into revealing passwords.