The FBI warned that cybercriminals are increasingly using the Kali365 phishing kit to hijack Microsoft 365 accounts while bypassing multi-factor authentication protections.
According to investigators, Kali365 operates as a phishing-as-a-service platform distributed through Telegram channels and underground cybercrime communities. Instead of stealing passwords directly, the toolkit focuses on stealing OAuth access tokens and authenticated sessions.
Researchers warned that this approach allows attackers to access Microsoft 365 accounts even after victims successfully complete MFA verification.
The warning highlights the growing shift toward token-based phishing attacks targeting enterprise cloud environments.
Kali365 Uses Device Code Phishing Techniques
The Kali365 phishing kit abuses Microsoft’s legitimate device code authentication workflow.
Microsoft originally designed the feature for devices with limited input capabilities, including smart TVs, printers, conference systems, and IoT hardware. Users authenticate those devices by entering a short authorization code through Microsoft’s official login portal.
Attackers exploit that process by generating authorization codes themselves and then tricking victims into entering them through phishing emails or fake login requests.
Researchers said attackers often impersonate trusted services such as:
- SharePoint
- Microsoft 365
- Adobe Acrobat Sign
- DocuSign
Once victims enter the authorization code and complete MFA verification, Microsoft issues OAuth access tokens tied to the attacker-controlled session.
That process allows attackers to gain account access without stealing passwords directly.
Stolen Tokens Allow Long-Term Access
Researchers warned that OAuth token theft creates serious security risks because attackers can bypass traditional login protections entirely.
Successful attacks may provide access to:
- Outlook mailboxes
- Teams conversations
- OneDrive files
- SharePoint environments
- Connected cloud applications
Security researchers also reported that attackers sometimes create malicious inbox rules designed to hide suspicious activity inside compromised mailboxes.
In some incidents, threat actors reportedly registered new devices inside victim environments to maintain persistent access.
The Kali365 phishing kit also allegedly includes advanced adversary-in-the-middle capabilities that capture authenticated browser sessions and session cookies after users complete MFA verification.
Researchers warned that these techniques make modern phishing attacks significantly harder to detect compared to traditional credential theft campaigns.
FBI Urged Organizations to Restrict Device Code Authentication
The FBI recommended that organizations restrict or disable device code authentication flows whenever possible.
Investigators also advised companies to:
- Monitor suspicious OAuth token activity
- Review unauthorized device registrations
- Apply Conditional Access policies
- Restrict authentication transfer workflows
- Audit device code authentication usage
Researchers explained that token theft and device code phishing attacks have increased rapidly during the past year as cybercriminals move away from ordinary password harvesting techniques.
Several phishing-as-a-service platforms now reportedly use similar methods against Microsoft 365 and Entra environments.
Conclusion
The Kali365 phishing kit shows how modern phishing operations continue evolving beyond traditional credential theft. Instead of targeting passwords directly, attackers increasingly focus on OAuth tokens and authenticated sessions capable of bypassing MFA protections.
The FBI warning also highlights how phishing-as-a-service platforms are making advanced attack methods accessible to a much larger number of cybercriminals. As token-based attacks continue growing, organizations may need stronger identity protections and tighter authentication controls across cloud environments.


0 responses to “Kali365 Phishing Kit Bypasses Microsoft 365 MFA”