FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI says Kali365 uses device-code phishing to hijack Microsoft 365 accounts and bypass MFA.
Intelligence analysis by GPT-5.4 Mini

Kali365 sells low-skill attackers a ready-made way to break into Microsoft 365 and Entra accounts by abusing OAuth device-code logins. The FBI says it can capture tokens, hide activity, and extend access through inbox rules and new device registrations.
Kali365 is like a crime kit sold to people who want to break into email accounts. Instead of stealing a key, it tricks a person into opening the door for them.
The trick uses a real Microsoft login page and a short code. If the person enters the code and finishes the extra safety check, the attacker gets a pass that works like a copied wristband at an event.
The FBI says companies should block this kind of login when possible and watch for strange sign-ins or new devices. That can help stop the thief even after the trick has started.
Analysis
What the FBI says
The FBI warns that Kali365 is a phishing-as-a-service platform built to hijack Microsoft 365 accounts by abusing OAuth device-code authentication. According to the FBI PSA, the service first appeared in April 2026 and is promoted through Telegram channels to criminals who want an easier path into Microsoft accounts without needing passwords or MFA codes.
How the attack works
The core trick is device-code phishing. Attackers start the Microsoft device authorization flow themselves, generate a code, and then send the victim to the legitimate Microsoft login page to enter it. If the victim completes the login and MFA prompt, Microsoft issues an OAuth token that gives the attacker access to the account session. That means the attacker can reach the same cloud apps the user can, including Microsoft 365 and other connected SaaS services.
Why Kali365 stands out
The FBI says Kali365 packages this into a service with features aimed at lower-skill operators, including AI-generated phishing lures, campaign templates, victim-tracking dashboards, and token capture. Arctic Wolf reported similar activity in April after seeing campaigns that targeted Microsoft 365 users with emails leading them to the device-code login portal. In those cases, attackers gained mailbox access, created inbox rules to hide their activity, and sometimes registered new devices for longer-term access.
Broader trend and response
Arctic Wolf described Kali365 as an organized business with admins, resellers, and affiliates. The platform also offers an adversary-in-the-middle mode called Cookie Link, which proxies victims through attacker-controlled infrastructure to capture authenticated sessions, cookies, and tokens. The FBI recommends restricting or blocking device-code authentication with Conditional Access where possible, auditing device-code usage, and blocking authentication transfer policies. It also urges reporting incidents to the IC3 and preserving phishing emails, suspicious logins, and unauthorized device registrations.
Key points
- The FBI says Kali365 is a phishing-as-a-service platform aimed at Microsoft 365 and Entra accounts.
- It abuses OAuth device-code authentication to steal session tokens and bypass MFA.
- The service is distributed through Telegram and appears designed for low-skill attackers.
- Arctic Wolf reported campaigns that used the method to access mailboxes, hide activity, and add devices.
- The FBI recommends restricting device-code authentication, auditing its use, and reporting incidents to the IC3.



