LIVE NEWS
  • Italy seizes gold, luxury villas and cash tied to Sicilian Mafia drug-trafficking
  • Dogecoin Slips Below 10 Cents With More Downside Ahead
  • Microsoft Condemns “Uncoordinated” Zero Day Disclosures
  • A new report shows how close American households are to the financial edge : NPR
  • Six in 10 Neets have never had a job, says Alan Milburn, as he warns of ‘generational faultline’ – UK politics live | Politics
  • Goldman Sachs Just Did a Huge Shake Up of Its Crypto Portfolio. Here’s What It Means.
  • Xi’s summit diplomacy reveals an increasingly confident China
  • Millions of planets might form around supermassive black holes
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»FBI Warns ‘Kali365’ Phishing Kit Hijacks Microsoft 365 OAuth Tokens
Cybersecurity

FBI Warns ‘Kali365’ Phishing Kit Hijacks Microsoft 365 OAuth Tokens

primereportsBy primereportsMay 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
FBI Warns ‘Kali365’ Phishing Kit Hijacks Microsoft 365 OAuth Tokens
Share
Facebook Twitter LinkedIn Pinterest Email


A new phishing-as-a-service (PhaaS) platform called Kali365 is being distributed in the wild, primarily via Telegram, the FBI has warned.

First detected in April 2026, Kali365 provides cyber threat actors access to AI-generated phishing lures, automated campaign templates real-time targeted individual and entity tracking dashboards.

It also enables technically low-level individuals to capture OAuth tokens – Microsoft 365 access tokens – and bypass multifactor authentication (MFA) protocols without intercepting the user’s credentials.

Through the Kali365 platform subscription, cyber threat actors can gain persistent access to targeted individuals/entities’ Microsoft 365 environments.

Kali365 Attack Chain

In a typical attack chain, detailed by the FBI in an advisory published on May 21, an attacker initiates the scam by sending a phishing email that impersonates trusted cloud productivity and document-sharing services.

This email contains a device code along with instructions to visit a legitimate Microsoft verification page and enter the code.

Victims navigate to the real Microsoft page and paste in the device code, thereby unknowingly authorizing the attacker’s device to access their account.

The attacker then captures OAuth access and refresh tokens, which grants them access to the targeted individuals’ or entities’ Microsoft 365 account.

With these tokens in hand, the attacker can now access Microsoft 365 services such as Outlook, Teams and OneDrive without needing a password or completing any additional MFA challenges, thus establishing persistence in the compromised account.

Mitigating Kali365-Like Threats

To mitigate the threat of being targeted by Kali365-enabled cybercriminals, the FBI recommended the following measures:

  • Restrict device code flow to limit or block device authentication codes
  • Create a conditional access policy to block device code flow for all users, with limited exceptions for required business processes
  • Block authentication transfer policies to prevent users from transferring authentication from computers to mobile devices
  • Exclude emergency access accounts to prevent lockouts

Image credits: Ed Hardie / Unsplash
      

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBest Low Cap Crypto Coins to Buy Now
Next Article HYPE Rally Accelerates Above $60 As High-Profile Whale Quietly Builds His Position
primereports
  • Website

Related Posts

Cybersecurity

Microsoft Condemns “Uncoordinated” Zero Day Disclosures

May 28, 2026
Cybersecurity

Whoop vs. Fitbit Air: I’ve tested both trackers for health and fitness, and this model wins

May 27, 2026
Cybersecurity

Can you enforce strong Active Directory password rules without frustrating users?

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

Together AI Open-Sources OSCAR: An Attention-Aware 2-Bit KV Cache Quantization System for Long-Context LLM Serving

May 26, 20267 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20265 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Italy seizes gold, luxury villas and cash tied to Sicilian Mafia drug-trafficking
  • Dogecoin Slips Below 10 Cents With More Downside Ahead
  • Microsoft Condemns “Uncoordinated” Zero Day Disclosures
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.