Kali365: The FBI's Latest Phishing Nightmare Is Selling MFA Defeat as a Service

Kali365: The FBI's Latest Phishing Nightmare Is Selling MFA Defeat as a Service

A new phishing-as-a-service platform is exploiting OAuth device code flows to silently drain Microsoft 365 accounts — no password required.

Written by OutOfToken AI

June 3, 2026 · 4 min read · Synthesized from reporting by BleepingComputer · How this works

AI Likely Accurate · 8/10

The FBI has issued a public service announcement warning organizations about Kali365, a phishing-as-a-service platform that emerged in April 2026 and is rapidly gaining traction among cybercriminals targeting Microsoft 365 infrastructure. Unlike conventional credential-harvesting operations, Kali365 doesn't bother stealing passwords — it steals something far more valuable: live session tokens. The platform weaponizes OAuth device code authentication, a legitimate Microsoft feature designed for devices without keyboards, and turns it into a master key that renders multi-factor authentication effectively useless.

How Device Code Phishing Actually Works

OAuth device code authentication was built for smart TVs, printers, and IoT devices that can't easily handle a browser-based login flow. A device requests a short alphanumeric code from Microsoft, displays it to the user, and instructs them to visit a login URL to authorize the session. Kali365 hijacks this process by generating a legitimate device code through Microsoft's own authentication servers, then socially engineering the victim into entering that code on a spoofed or manipulated page. Once the target authorizes the code, the attacker's application receives a fully authenticated access token — one that carries all the permissions of the logged-in user, bypasses MFA entirely, and persists until manually revoked. The victim's password is never touched, and most security tooling never flags it.

A Platform Built for Scale

Kali365 is distributed via Telegram, following the now-standard playbook of commoditized cybercrime tooling. The platform abstracts the technical complexity of device code phishing into a point-and-click operation, lowering the barrier for actors who lack the sophistication to build their own infrastructure. Once access is established, operators face an open door: exfiltrating emails and files, launching internal spear-phishing campaigns from trusted accounts, committing financial fraud, or deploying ransomware. The FBI's PSA specifically highlights data theft, extortion, and ransom as documented downstream consequences — a full spectrum of monetization options that makes Kali365 attractive across multiple threat actor profiles, from financially motivated criminals to nation-state-adjacent groups.

"Kali365 doesn't crack passwords or race against MFA timers — it exploits trust in Microsoft's own authentication architecture to hand attackers a token that looks indistinguishable from a legitimate login."

Why This Attack Vector Is Accelerating

Device code phishing is not new — Microsoft and security researchers documented its misuse as far back as 2021, and nation-state actors including Russia's Cozy Bear have deployed variants against high-value targets. What is new is the full commoditization of the technique. Kali365 represents the maturation of a sophisticated attack method into an off-the-shelf product, which historically signals a sharp increase in attack volume. Organizations relying on MFA as their primary account-protection mechanism face a structural problem: MFA was never designed to defend against token theft at the OAuth layer. Conditional access policies, continuous access evaluation, and device compliance checks are the actual controls that can interrupt a stolen token's utility — but many enterprise deployments haven't fully enabled them.

The FBI's warning about Kali365 is a signal that device code phishing has crossed from advanced persistent threat tradecraft into mainstream criminal infrastructure. Security teams should audit which applications in their Microsoft 365 environments are permitted to use device code flows and restrict the grant type where it isn't operationally necessary. Microsoft's Conditional Access policies can block device code authentication outright for user accounts — a configuration step that is straightforward but far from universally deployed. As PhaaS platforms continue to industrialize formerly nation-state-grade techniques, the gap between enterprise security posture and attacker capability will only close if defenders stop treating MFA as a finish line and start hardening the authentication layer beneath it.

Editorial Note

BleepingComputer is a reputable cybersecurity news outlet with a track record of accurate reporting on threats. FBI warnings about phishing services and OAuth-based attack methods are consistent with documented threat trends in 2024. The technical details about device code authentication and MFA bypass align with known attack vectors, though independent confirmation from official FBI statements would provide higher certainty.

Claim Tracker

AI-assessed

UnverifiedKali365 phishing-as-a-service platform emerged in April 2026

Future date indicates either a factual error or speculative article; requires verification of actual emergence date

VerifiedKali365 weaponizes OAuth device code authentication to bypass MFA

OAuth device code flow is a documented Microsoft feature; social engineering attacks against it are established threat vectors

VerifiedOAuth device code authentication was designed for devices like smart TVs, printers, and IoT devices

Accurate description of the legitimate use case for device code flow per Microsoft OAuth specifications

UnverifiedKali365 generates legitimate device codes through Microsoft's authentication servers

Specific operational details about how the platform generates codes require additional verification

UnverifiedFBI issued a public service announcement about Kali365

No official FBI PSA link or document reference provided in excerpt

Ask AI about this story

// discussion

sign in to join the discussion