www.malwarebytes.com 5/27/2026, 12:08:40 PM · external

FBI warns of Kali365 phishing kit stealing Microsoft 365 tokens

FBI warns of Kali365 phishing kit stealing Microsoft 365 tokens
CyberSIXT Evidence Panel
Primary Source ic3.gov

THE Kali365 phishing kit, highlighted by the FBI, is a phishing-as-a-service platform that targets Microsoft 365 accounts by stealing access tokens instead of passwords. This method is effective against both organizations and individual users, as it bypasses multi-factor authentication (MFA) and provides attackers with ongoing access to user accounts, requiring minimal technical skill to use.

Victims are misled by phishing messages that appear legitimate, ultimately allowing attackers to gain OAuth tokens for persistent access to Microsoft services. Users are advised to be wary of unsolicited requests for device codes, to read prompts carefully, and monitor logged-in devices to protect their accounts.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline