Malware · 104 days ago
Kali365 Expands Beyond Microsoft 365 Tokens Kali365 has moved past a Microsoft 365 token-theft niche into a broader account-compromise service. The change matters because the same device-code phishing flow that steals an M365 session can now be turned against cloud identities and IdPs, so a mailbox problem starts to look like a cloud-admin problem.
Arctic Wolf says the kit now targets AWS, Okta, Xerox DocuShare, and Russian services including MAX Messenger. That widens the blast radius from email access to identity and control-plane access, and the MAX target hints the operators may also be using account takeovers for propagation, not just one-off credential theft.
For teams that rely on Microsoft, Okta, AWS, or federated sign-in, the defensive model has to assume the token-grab workflow is portable across services. Patching one product or teaching users to watch for one brand of phishing is no longer enough to describe the risk.
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions… EPSS 15% (95th percentile).
CISA federal remediation date May 30 · date passed
Timeline Sources 10 sources covering this story
Dark Reading Jun 3
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
From solely targeting Microsoft 365, the phishing-as-a-service platform now targets AWS, Okta, and Russian platforms.
The Hacker News May 28
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
ThreatsDay Bulletin: Kali365 MFA bypass, Azure priv-esc, FIFA scams, OAuth theft, fake installers, and supply chain attacks.
Graham Cluley May 26
FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required
So, you've enabled multi-factor authentication.
Cybersecurity Dive May 26
FBI warns about PhaaS platform used to access Microsoft 365 environments
Device code phishing enabled hackers to bypass multifactor authentication without credentials.
BleepingComputer May 25
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
Infosecurity Magazine May 25
FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens
The Kali365 phishing-as-a-service platform lowers the barrier of entry for cybercriminals, said the FBI
CyberScoop May 22
FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications.
The Record from Recorded Future May 22
FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.
CSO Online May 22
FBI warns of Kali Oauth stealers
A new phishing attack platform endangers Microsoft environments.
Help Net Security May 22
Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security
Kali365 is targeting Microsoft 365 users through device code phishing, using OAuth token theft and Telegram-based distribution.
Entities Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-23
Editions
Malware · 104 days ago
Kali365 Expands Beyond Microsoft 365 Tokens Kali365 has moved past a Microsoft 365 token-theft niche into a broader account-compromise service. The change matters because the same device-code phishing flow that steals an M365 session can now be turned against cloud identities and IdPs, so a mailbox problem starts to look like a cloud-admin problem.
Arctic Wolf says the kit now targets AWS, Okta, Xerox DocuShare, and Russian services including MAX Messenger. That widens the blast radius from email access to identity and control-plane access, and the MAX target hints the operators may also be using account takeovers for propagation, not just one-off credential theft.
For teams that rely on Microsoft, Okta, AWS, or federated sign-in, the defensive model has to assume the token-grab workflow is portable across services. Patching one product or teaching users to watch for one brand of phishing is no longer enough to describe the risk.
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions… EPSS 15% (95th percentile).
CISA federal remediation date May 30 · date passed
Timeline Sources 10 sources covering this story
Dark Reading Jun 3
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
From solely targeting Microsoft 365, the phishing-as-a-service platform now targets AWS, Okta, and Russian platforms.
The Hacker News May 28
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
ThreatsDay Bulletin: Kali365 MFA bypass, Azure priv-esc, FIFA scams, OAuth theft, fake installers, and supply chain attacks.
Graham Cluley May 26
FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required
So, you've enabled multi-factor authentication.
Cybersecurity Dive May 26
FBI warns about PhaaS platform used to access Microsoft 365 environments
Device code phishing enabled hackers to bypass multifactor authentication without credentials.
BleepingComputer May 25
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
Infosecurity Magazine May 25
FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens
The Kali365 phishing-as-a-service platform lowers the barrier of entry for cybercriminals, said the FBI
CyberScoop May 22
FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications.
The Record from Recorded Future May 22
FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.
CSO Online May 22
FBI warns of Kali Oauth stealers
A new phishing attack platform endangers Microsoft environments.
Help Net Security May 22
Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security
Kali365 is targeting Microsoft 365 users through device code phishing, using OAuth token theft and Telegram-based distribution.
Entities Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-23
Editions