FBI Warns Kali365 PhaaS Kit Is Hijacking Microsoft 365 Accounts Without Stealing a Single Password

FBI Warns Kali365 PhaaS Kit Is Hijacking Microsoft 365 Accounts Without Stealing a Single Password

The FBI’s Internet Crime Complaint Center (IC3) has issued an urgent public advisory warning organisations and individuals about Kali365 a Phishing-as-a-Service (PhaaS) platform that can silently hijack Microsoft 365 accounts without ever capturing a password, and bypass multi-factor authentication in the process.

First detected in April 2026, Kali365 has been circulating primarily through Telegram, where it is sold to cybercriminals on a subscription basis reportedly for as little as $250 per month or $2,000 per year, paid in untraceable cryptocurrency. The FBI confirmed the platform has already been used in hundreds of documented attacks across North America and Europe, with targets including education, healthcare, finance, and government sectors.

How the Attack Works

Kali365 exploits a legitimate Microsoft feature called device code authentication a sign-in mechanism originally designed for devices that are difficult to type on, such as smart TVs or shared kiosks. In a typical Kali365 attack, a victim receives a phishing email impersonating a trusted cloud service such as Adobe Acrobat Sign, DocuSign, or Microsoft SharePoint. The email instructs the victim to visit a genuine Microsoft verification page and enter a short code.

The page is real. The URL is legitimate. The SSL certificate is valid. The victim types the code and in doing so, unknowingly authorises the attacker’s device to access their Microsoft 365 account.

The attacker receives OAuth access tokens and refresh tokens tied to the victim’s account. These tokens grant persistent access to Outlook, OneDrive, Teams, and connected enterprise services without the attacker ever knowing the victim’s password. MFA is irrelevant, because the authentication check was passed by the victim themselves before the token was intercepted.

Who Is at Risk?

According to security firm Arctic Wolf, which published a technical deep-dive on Kali365 in April, the platform supports 15 languages including Arabic, Chinese, French, German, Japanese, and Spanish indicating a deliberate effort to scale attacks internationally. Financial services organisations are explicitly listed among targeted sectors.

What makes Kali365 particularly dangerous is the audience it enables. The FBI noted that the platform lowers the technical barrier for attackers, providing AI-generated phishing lures, automated campaign templates, real time targeting dashboards, and OAuth token capture capabilities to individuals who would previously have lacked the skills to run such an operation.

What Organisations Should Do Now

The FBI recommends taking the following actions immediately:

  • Restrict or block device code flow for all users except those with a verified business requirement
  • Create conditional access policies that prevent device code authentication by default
  • Block authentication transfer policies to prevent session migration from desktop to mobile
  • Switch to phishing-resistant MFA methods such as FIDO2 hardware security keys
  • Audit existing OAuth token grants and revoke any unrecognised access
  • Train employees to recognise device code phishing specifically that entering a code on a genuine Microsoft page does not guarantee the request is legitimate

Indian enterprises should note that Kali365-enabled compromise of a Microsoft 365 account could constitute a reportable personal data breach under DPDP Act 2023, Section 8(5), triggering CERT-In’s six-hour incident notification obligation. Compliance teams should review their M365 access governance policies as a matter of urgency.

Leave a Reply

Your email address will not be published.