Malware & Tooling · Credential Theft

Kali365 Expands Beyond Microsoft 365 Tokens

Kali365 has moved past a Microsoft 365 token-theft niche into a broader account-compromise service. The change matters because the same device-code phishing flow that steals an M365 session can now be turned against cloud identities and IdPs, so a mailbox problem starts to look like a cloud-admin problem.

Arctic Wolf says the kit now targets AWS, Okta, Xerox DocuShare, and Russian services including MAX Messenger. That widens the blast radius from email access to identity and control-plane access, and the MAX target hints the operators may also be using account takeovers for propagation, not just one-off credential theft.

For teams that rely on Microsoft, Okta, AWS, or federated sign-in, the defensive model has to assume the token-grab workflow is portable across services. Patching one product or teaching users to watch for one brand of phishing is no longer enough to describe the risk.

10 sources · Jun 3

CVE-2026-8398

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions… EPSS 15% (95th percentile).

CISA federal remediation date May 30 · date passed

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-23

Every edition of this story: Kali365 Expands Beyond Microsoft 365 Tokens