FBI warns of Kali phishing scam affecting Microsoft OAuth tokens; warns: “Kali365 lowers the barrier to entry and gives less technical attackers access to AI-generated phishing lures”



  • FBI flags Kali365, a phishing kit sold on Telegram that steals Microsoft 365 OAuth tokens and bypasses MFA
  • Victims are tricked into entering device codes on legitimate Microsoft pages, unknowingly granting the attacker access to Outlook, Teams, and OneDrive.
  • Mitigation steps include restricting device code flow, enforcing conditional access policies, auditing usage, and blocking authentication pass-through policies.

The FBI has warned of a new phishing kit that “lowers the barrier to entry” and allows even low-skilled malicious actors an easy way to compromise people’s Microsoft 365 accounts.

In a public service announcement (PSA), Microsoft said that a new phishing kit, called Kali365, began circulating on Telegram in April 2026. It is advertised as an easy way to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) without intercepting user credentials.

Leave a Comment

Your email address will not be published. Required fields are marked *