What is Kali365? FBI warns of Telegram-based phishing toolkit targeting Microsoft 365 users

What is Kali365? FBI warns of Telegram-based phishing toolkit targeting Microsoft 365 users

The Federal Bureau of Investigation (FBI) has alerted organizations about a newly discovered cybercrime platform known as Kali365, which is being utilized to compromise Microsoft 365 accounts by bypassing multi-factor authentication (MFA) safeguards. Unlike traditional phishing attacks that primarily focus on stealing passwords, Kali365 specifically targets the user's authentication process for cloud services, making these attacks more difficult to detect and mitigate, even after a password change. Kali365 operates as a "Phishing-as-a-Service" (PhaaS) platform, enabling cybercriminals to access ready-made phishing tools instead of having to create them independently. The FBI noted that this toolkit emerged in April 2026 and is being distributed via Telegram channels. Its primary risk lies in its ability to lower the barrier of entry for cybercriminals, allowing even those with limited technical expertise to launch attacks against Microsoft 365 users. This platform reportedly provides features such as AI-generated phishing emails, pre-made templates, automated campaign tools, real-time victim tracking, and mechanisms for capturing OAuth tokens. The attack process begins with a phishing email that appears to originate from a reputable cloud service or document-sharing platform. Rather than directing users to a counterfeit login page, the email supplies a device code for entry on a legitimate Microsoft login page, enhancing the attack's deceptive nature. As users engage with a genuine Microsoft page, the login process may seem entirely normal. Once a victim inputs the code and completes the authentication, they unwittingly grant access to the attacker’s device. Kali365 then captures OAuth access and refresh tokens, enabling the attacker to infiltrate the victim’s Microsoft 365 account. MFA is intended to safeguard accounts even when passwords are compromised, yet Kali365 circumvents this by using token-based authentication. Once an attacker gains access to valid OAuth tokens, they can enter services like Outlook, Teams, and OneDrive without needing the user's password again. Consequently, changing the password might not eliminate the attacker’s access if the stolen tokens remain valid, allowing continued entry. For organizations, a compromised Microsoft 365 account can lead to unauthorized access to emails, files, internal communications, and shared documents. This access can facilitate business email compromise, data theft, lateral movement within the organization, or additional phishing schemes targeting employees, clients, and vendors. The FBI emphasizes that Kali365 can enable attackers to maintain long-term access to compromised accounts, underscoring the importance of early detection. In response, the FBI advises organizations to reassess their Microsoft 365 authentication configurations, particularly concerning device code flow authentication. Security teams should consider restricting or disabling this authentication method where it is unnecessary, enforce stricter conditional access policies, and audit the necessity of device code-based logins for business functions. Additionally, the agency recommends blocking authentication transfers between devices and monitoring for unusual login activities or unauthorized session creation. Organizations are also urged to ensure that emergency access accounts remain accessible while implementing these restrictions.

Sources : Business Today

Published On : Jun 17, 2026, 06:10

Computing
Memory Chip Crisis: Musk and Cook Sound the Alarm on Unprecedented Price Hikes

In a startling revelation, Elon Musk has expressed his agreement with Apple CEO Tim Cook regarding the extraordinary ris...

Business Insider | Jun 26, 2026, 17:25
Memory Chip Crisis: Musk and Cook Sound the Alarm on Unprecedented Price Hikes
Streaming
Netflix Enforces Unique Email Requirement for User Profiles

In a recent experience, a Netflix user faced a frustrating situation when trying to access the platform. With only minut...

Ars Technica | Jun 26, 2026, 18:20
Netflix Enforces Unique Email Requirement for User Profiles
Startups
House Committee Issues Subpoena to Billionaire Leon Black Amid Epstein Inquiry

In a dramatic turn of events, the House Oversight Committee has summoned billionaire Leon Black during a confidential in...

Business Insider | Jun 26, 2026, 18:50
House Committee Issues Subpoena to Billionaire Leon Black Amid Epstein Inquiry
Startups
Tennis Star Novak Djokovic Joins General Atlantic as Strategic Advisor

Tennis champion Novak Djokovic has been appointed as a global strategic advisor for General Atlantic, a prominent privat...

TechCrunch | Jun 26, 2026, 19:45
Tennis Star Novak Djokovic Joins General Atlantic as Strategic Advisor
AI
OpenAI Rolls Out New AI Models with Restrictions Amid U.S. Government Guidance

On Friday, OpenAI unveiled three new artificial intelligence models, announcing that their initial release will be restr...

CNBC | Jun 26, 2026, 17:15
OpenAI Rolls Out New AI Models with Restrictions Amid U.S. Government Guidance
View All News