FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Incidents: Kali365 phishing toolkit bypasses MFA via OAuth device codes, enabling persistent access to Microsoft 365 accounts for data theft and ransomware.
Deep Analysis and Expert Commentary
Kali365 represents a significant evolution in phishing techniques, leveraging OAuth device code flows to circumvent MFA. Unlike traditional credential theft, this method abuses Microsoft’s device authorization API, requiring victims to paste a code generated by the attacker’s platform. The attack path involves: (1) phishing lures impersonating enterprise services, (2) redirecting victims to Microsoft’s legitimate device code page, and (3) capturing OAuth tokens for persistent access. Affected scope includes any organization using Microsoft 365, particularly those reliant on MFA for security. Mitigations include monitoring OAuth app consent grants, restricting third-party app permissions, and educating users on device code phishing. The FBI’s warning underscores the tool’s low barrier to entry ($250/month) and its rapid proliferation via Telegram, making it accessible to less-technical attackers.
Action Items
- Monitor and audit OAuth app consent grants in Microsoft 365 environments.
- Restrict third-party app permissions to minimize exposure to token theft.
- Educate users on recognizing device code phishing attempts and reporting suspicious activity.
Original Article Brief Intro
CyberScoop · 2026-05-22 · Incidents: Kali365 phishing toolkit bypasses MFA via OAuth device codes, enabling persistent access to Microsoft 365 accounts for data theft and ransomware.
Related Terms and Notes
Techniques / TTPs
- Kali365 — A phishing-as-a-service platform that automates OAuth device code phishing attacks against Microsoft 365 users.
- Phishing
- Phishing-as-a-service
Context Notes
- Kali365
- MFA bypass
- Microsoft 365
- OAuth
- OAuth device code — A flow in OAuth 2.0 that allows users to authorize devices without a browser by entering a code.