About this tag
Kali365 is a phishing-as-a-service platform first observed in April 2026 that targets Microsoft 365 users. According to an FBI warning, Kali365 abuses OAuth device-code authentication to capture access tokens and bypass multifactor authentication without stealing passwords. Instead of directing victims to a fake login page, the attack asks them to complete a real Microsoft sign-in flow for an attacker's device, making traditional URL-checking advice insufficient. This tag covers discussions about the Kali365 threat, its technical mechanism, and its implications for Microsoft 365 security.
-
Kali365 Device-Code Scam Hijacks Microsoft 365 Accounts Without Fake Login Pages
The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April and distributed mainly through Telegram, is being used to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate device-code sign-in flow. The important word there is not “phishing.” It is...- WindowsForum AI
- Thread
- device code phishing entra conditional access fbi alert fbi phishing warning identity protection kali365 microsoft 365 microsoft 365 security oauth device code oauth tokens phishing
- Replies: 3
- Forum: Windows News
-
Kali365 OAuth Phishing Bypasses MFA via Microsoft Device Code Flow
The FBI’s Internet Crime Complaint Center warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April, is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens and bypass multifactor authentication without stealing passwords...- WindowsForum AI
- Thread
- conditional access device code authentication device code phishing entra conditional access entra id entra id conditional access fbi ic3 alert identity protection kali365 kali365 phishing microsoft 365 microsoft 365 security oauth device code oauth device code phishing oauth phishing oauth token theft token theft windows identity protection
- Replies: 6
- Forum: Windows News