Kali365 hands attackers persistent access to Outlook, Teams and OneDrive, bypassing multi-factor authentication. The FBI warned on May 21 that the phishing-as-a-service platform captures OAuth device codes and steals authorization and refresh tokens, letting intruders read email, grab files and use collaboration services without passwords or repeated MFA prompts. First seen in April and sold by subscription on Telegram, Kali365 packages AI-generated phishing lures, templates and real-time dashboards, lowering the technical bar for account takeover, the bureau said. That makes the advisory relevant to households, small businesses and large organizations that rely on Microsoft device code authentication flows.
Households, small businesses and large organizations face persistent account takeover risk because Kali365 captures the tokens that prove a user has authenticated, the FBI said.
How the attack works
The FBI's Internet Crime Complaint Center laid out the attack chain in a Public Service Announcement. First, an attacker sends a phishing email that impersonates a trusted cloud or document sharing service and includes a device code with instructions to visit Microsoft's legitimate verification page. If the target pastes the device code into that real page, the victim unknowingly grants the attacker permission. The attacker then captures access and refresh tokens. Those tokens let the attacker access Microsoft 365 services continuously without needing the victim's password or triggering additional MFA challenges.
The bureau said Kali365 also provides AI generated phishing lures, ready made attack templates and real time tracking dashboards. That package lets less skilled attackers run targeted campaigns and follow which victims have granted permissions. The FBI and cybersecurity outlets said Kali365 was first observed in April and is primarily distributed through Telegram. Cybersecurity software company Bitdefender described it as a subscription service for scammers.
The consequences the FBI named are familiar to defenders: data theft, fraud, extortion and facilitation of ransomware. Because the theft targets authorization tokens rather than passwords, attackers can continue to access accounts even when typical password or MFA protections remain in place, the agency warned.
Defensive steps and reporting
The FBI gave concrete configuration and operational steps for organizations that use Microsoft 365.
The agency recommended creating conditional access policies to block device code flow for most users, while first auditing existing device code usage to identify legitimate dependencies. The bureau also advised blocking authentication transfers between computers and mobile devices, and excluding emergency access accounts from blocks to prevent lockouts.
If full restriction of device code flow isn't possible, the FBI recommended limiting exceptions to narrowly defined business needs.
Microsoft told Nexstar that it agrees with the FBI's guidance and urged customers to follow standard best practices. Microsoft recommended training users to spot phishing attempts, avoiding opening files from unknown senders and keeping operating systems and applications updated with the latest security fixes. Microsoft also said it's actively working to disrupt the criminal ecosystems behind phishing as a service and account takeover activity to protect customers.
Operational teams should treat token theft as a high severity incident. First, review account sessions and revoke any unknown or suspicious refresh tokens and active sessions. Second, audit third party app permissions and remove any unfamiliar consent grants. Third, narrow conditional access rules and monitor for device code flows that don't match legitimate business processes. Fourth, log and preserve phishing emails and email headers for investigation.
The FBI urged anyone who believes they have been targeted to report incidents to the Internet Crime Complaint Center at IC3.gov. Reports should include the phishing email and email headers, suspicious login activity such as timestamps and IP addresses.
Related Articles
- Makhlouf: ECB committed to 2% target, June unclear
- Dudley: Case for Fed Rate Cuts Weak as Core PCE Nears 2%
- Trader Joe's May launches: Carne Asada $11.99/lb, gummy worms with 14g fiber
If you suspect token theft, report it at IC3.gov. Include the phishing email and headers, plus any suspicious timestamps and IP addresses to help investigators.
This article was created with AI assistance.