A dangerous new cybercrime tool is making waves across the security community — and it has rendered one of the most trusted defences in digital security nearly powerless. Kali365, a subscription-based Phishing-as-a-Service (PhaaS) platform, is hijacking Microsoft 365 accounts at scale without ever stealing a single password — and it defeats multi-factor authentication (MFA) in the process.

On May 21, 2026, the FBI issued a formal public service announcement (PSA Alert Number I-052126-PSA) warning organisations worldwide about the rapidly growing threat. By the time the advisory was published, hundreds of organisations had already been compromised in April alone.

What Is Kali365?

Kali365 is a Phishing-as-a-Service platform — a subscription-based criminal product that packages sophisticated hacking capabilities into an easy-to-use toolkit, removing the need for deep technical expertise. The platform was first observed in April 2026 and quickly gained traction among cybercriminals due to its accessibility and effectiveness.

Sold primarily through Telegram cybercrime channels, Kali365 is available for as little as $250 for 30 days or $2,000 for an annual subscription — a remarkably low price point for capabilities that can defeat enterprise-grade security controls. The platform operates like a legitimate business, with administrators managing product development, resellers promoting the service to other threat actors, and affiliates conducting phishing campaigns using the prebuilt infrastructure.

The Attack: How It Works

Unlike conventional phishing attacks that attempt to steal usernames and passwords, Kali365 takes a fundamentally different approach — one that renders password managers, credential monitoring services, and standard MFA controls irrelevant.

The OAuth Device Code Phishing Method

The core technique exploits a legitimate Microsoft authentication feature called the OAuth device code flow — a mechanism originally designed to allow users to sign in to services on devices without a browser (such as smart TVs or gaming consoles).

Here is how the attack unfolds step by step:

  1. The Lure: The victim receives a phishing email impersonating a trusted cloud productivity or document-sharing service — such as Adobe Acrobat Sign, DocuSign, or SharePoint. The email contains a short numeric device code and instructions to enter it at a legitimate Microsoft verification page.
  2. The Trap: The victim visits Microsoft’s real authentication page (microsoft.com/devicelogin) — a genuine, legitimate site — and enters the provided code. Because they are on a real Microsoft page, no red flags are raised.
  3. The Handoff: By entering the code, the victim unknowingly authorises the attacker’s device. Microsoft then issues OAuth access and refresh tokens directly to the attacker’s infrastructure — with the victim’s own authentication completing the process.
  4. Persistent Access: The attacker now holds OAuth tokens that grant immediate, long-term access to the victim’s Microsoft 365 environment — including Outlook, Teams, OneDrive, and any connected SaaS applications — without ever needing a password or MFA code again.

The FBI captured this dynamic succinctly: the victim completes MFA themselves, unknowingly authenticating for the attacker rather than for their own session.

The “Cookie Link” Adversary-in-the-Middle Mode

Arctic Wolf researchers uncovered a second attack mode within Kali365, dubbed “Cookie Link.” In this method, victims receive a phishing email containing a link that transparently proxies their browser through attacker-controlled infrastructure. The victim authenticates normally through Microsoft’s real login page — including passing MFA — but the attacker’s servers capture the authenticated session cookies and tokens in real time. Both modes lead to the same outcome: full account access without credential theft.

Why MFA Alone Is No Longer Enough

The structural danger of Kali365 lies in what it does not do. Because no credentials are directly stolen, traditional security alerts — such as password breach notifications, credential monitoring alerts, and failed login warnings — are never triggered. The attack exploits legitimate authentication workflows, meaning the activity blends seamlessly into normal API and integration patterns.

Cory Michal, Chief Security Officer at AppOmni, explained the underlying vulnerability: OAuth tokens often operate as bearer credentials. If an attacker obtains them, they can be used as a single-factor access method without triggering an interactive login or MFA challenge, and the activity can appear indistinguishable from legitimate access.

This dramatically increases attacker dwell time — the window between a breach occurring and its detection — giving criminals extended, undetected access to sensitive data, communications, and business systems.

Scale and Targets

Security firms including Arctic Wolf and Proofpoint documented hundreds of attacks in April 2026 alone, with victims spanning multiple sectors across North America and Europe:

  • Manufacturing
  • Education
  • Government
  • Insurance
  • Financial Services
  • Healthcare

Critically, every one of those victim organisations was using MFA. The attack also presents risks to individual consumers — anyone with an Outlook, OneDrive, or personal Microsoft 365 subscription could be targeted using the same underlying technique.

Arctic Wolf noted that the campaign originated primarily from a single IP address, suggesting a centralised and organised operation, with researchers observing gradual infrastructure expansion and the deployment of new servers and access panels.

AI-Powered Phishing at Scale

One of the most alarming features of Kali365 is its use of artificial intelligence to generate high-fidelity phishing lures. The FBI noted that the platform lowers the barrier of entry by providing less-technical attackers with access to AI-generated phishing content, automated campaign templates, real-time victim tracking dashboards, and OAuth token capture capabilities.

This democratisation of sophisticated attack tools means that even low-skilled criminals can now launch advanced, targeted campaigns at scale — a trend that security researchers warn is accelerating across the broader PhaaS ecosystem.

Post-Compromise Activity

Once attackers obtain OAuth tokens, the post-compromise playbook is extensive. Documented attacker activity following successful Kali365 intrusions includes:

  • Mailbox access and email exfiltration — reading and stealing sensitive communications
  • Malicious inbox rules — creating hidden rules to suppress security notifications and extend dwell time
  • OneDrive file access — downloading sensitive proprietary data and documents
  • Teams monitoring — surveilling internal communications and business workflows
  • Unauthorised device registration — registering attacker-controlled devices within the victim’s Microsoft environment to extend persistent access
  • Token persistence — maintaining access even after victims change their passwords, as long as refresh tokens remain active

Security analysts have described this capability as the foundation for Business Email Compromise (BEC) 2.0 — attacks that move beyond simple email fraud into internal lateral movement and data theft.

Historical Context: A Growing Trend

Kali365 did not emerge in a vacuum. Proofpoint documented a sharp increase in device code phishing beginning in September 2025, when state-aligned threat actors — including groups linked to Russia — first adopted the technique at scale. By October 2025, financially motivated criminal groups had followed suit.

By February 2026, platforms like EvilTokens had fully commoditised the technique, and Huntress tracked more than 340 compromised organisations across five countries from a related campaign. Kali365 arrived in April 2026 as a more polished and feature-complete product in the same category. Cybersecurity firms Proofpoint, IBM, and Huntress have all confirmed that multiple services similar to Kali365 are currently in active development and deployment.

FBI and CISA Recommended Defences

The FBI and CISA have outlined several measures organisations should take to reduce their exposure to Kali365 and similar device code phishing attacks:

  1. Restrict or disable device code flow authentication where it is not operationally required
  2. Implement conditional access policies that block unauthorised device code usage
  3. Audit existing device code flow dependencies before applying restrictions to avoid service disruption
  4. Block authentication transfer between devices to prevent token relay abuse
  5. Maintain emergency access accounts to prevent lockouts during remediation
  6. Monitor for unusual sign-in and token usage patterns in Microsoft Entra ID (formerly Azure AD) logs
  7. Review and audit inbox rules for malicious suppression rules created by attackers
  8. Audit registered devices within Microsoft environments for unauthorised entries

Arctic Wolf additionally recommends implementing conditional access policies specifically targeting device code flows and providing targeted user awareness training about the risks of entering unfamiliar device codes, even on legitimate Microsoft pages.

What Individuals and Organisations Should Do Now

For organisations, the priority action is to evaluate whether device code authentication flow is needed for any business function. If it is not, it should be disabled immediately via Microsoft Entra conditional access policies. Security teams should also audit token issuance logs for anomalous access patterns and ensure that refresh token lifetimes are minimised.

For individual users, the key warning sign is any email or message asking you to visit microsoft.com/devicelogin and enter a code — unless you personally initiated a device sign-in. Legitimate Microsoft device flows are initiated by the user, not pushed via email. If you receive such a request unexpectedly, do not enter the code.

Conclusion

Kali365 represents a paradigm shift in the phishing threat landscape. By weaponising a legitimate Microsoft authentication mechanism, it has neutralised MFA as a standalone defence for Microsoft 365 environments — a security assumption that millions of organisations have relied upon for years.

The message from the FBI is clear: standard MFA configuration is no longer sufficient against current-generation phishing tooling. Organisations must move beyond password and one-time-code protections toward stronger identity controls, token lifecycle management, and continuous authentication monitoring.

As phishing platforms continue to evolve and lower the barrier of entry for attackers, the security community faces a pressing imperative: the defences of yesterday must be urgently upgraded to meet the threats of today.

About The Author