The United States Federal Bureau of Investigation (FBI) has issued an urgent warning about an emerging phishing-as-a-service (PhaaS) platform known as Kali365, which enables cybercriminals to hijack Microsoft 365 accounts while bypassing traditional multi-factor authentication (MFA) protections.
According to the FBI, Kali365 first appeared in April 2026 and is primarily distributed through Telegram-based cybercrime channels. The platform allows even low-skilled threat actors to launch sophisticated phishing campaigns using AI-generated lures, automated phishing templates, victim-tracking dashboards, and OAuth token theft capabilities.
Unlike conventional phishing attacks that focus on stealing usernames and passwords, Kali365 exploits Microsoft’s legitimate OAuth device-code authentication process. Victims are tricked into entering a device code on an authentic Microsoft verification page, unknowingly authorizing an attacker’s device to access their account. Once the authorization is completed, attackers obtain OAuth access and refresh tokens, granting persistent access to Microsoft 365 services such as Outlook, Teams, OneDrive, and SharePoint without needing passwords or MFA codes.
Security experts warn that the attack is particularly dangerous because users are redirected to a genuine Microsoft login page rather than a fake website, making the phishing attempt more difficult to detect. The use of legitimate Microsoft infrastructure significantly increases the likelihood that victims will trust the request and complete the authentication process.
The FBI noted that Kali365 lowers the barrier to entry for cybercriminals, enabling inexperienced attackers to conduct advanced phishing operations at scale. Researchers have observed growing adoption of the platform among threat actors seeking to compromise corporate and individual Microsoft 365 accounts.












