What is Kali365
Kali365 is a phishing-as-a-service platform built to target Microsoft 365 users. It hands attackers a ready-made kit: AI-generated lures, campaign templates, tracking dashboards, and a method to capture Microsoft 365 access tokens. The FBI issued a public warning after it was first seen in April 2026.
Kali365 does not always need to steal a password to create risk. Attackers can trick a user into authorizing access through Microsoft's own legitimate sign-in flow, then walk away with a valid access token. With that token, they can reach Microsoft 365 services even when multi-factor authentication is switched on.
Because the kit is a low-cost subscription distributed through Telegram, even low-skill attackers can run polished campaigns at scale. This is not a reason to panic. It is a reason to confirm a handful of settings in your environment are configured the way you'd expect.
Modern phishing is no longer just about stealing passwords. It is about stealing access. Kali365 captures a session token directly, so the usual warning signs – a wrong password, a missed MFA prompt – never fire.
Attack Methodology
Most of the steps below happen on real Microsoft infrastructure, which is exactly why a careful person can still be caught.
An employee gets an email that looks like it's from a trusted service — DocuSign, SharePoint, OneDrive, or Adobe. The content is often AI-generated, so it reads cleanly and on-brand.
The email directs the user to a genuine Microsoft sign-in page and asks them to enter a short verification code. The web address is real, so there's no fake URL for a careful person to catch.
The moment the user enters that code, they approve a sign-in the attacker started moments earlier. Microsoft hands back a valid access token to the attacker, not the user.
With that token, the attacker has working access to Outlook, Teams, OneDrive, and SharePoint. No password was stolen, no MFA prompt was failed, and the access tends to persist until the token is revoked.
Why MFA Doesn’t Prevent It
Most organizations treat MFA as the finish line. Attacks like Kali365 show that MFA is critical, but it is not the whole picture.
The technique abuses device-code authentication, a legitimate Microsoft 365 feature. Think of signing into a streaming app on a smart TV: the screen shows a code, you enter it on your phone, and the TV is logged in. Kali365 simply turns that flow against the user. The Microsoft login page can be real, the MFA prompt can be real, and the user can still unknowingly authorize the attacker's session.
- "We have MFA, so accounts are protected."
- "Our spam filter would catch a phishing email."
- "A fake login page would have a suspicious web address."
- The token is captured after a real MFA prompt, so MFA never blocks it.
- The lure links to a genuine Microsoft page, so there's nothing for a filter to flag as suspicious.
- The web address is real, because the sign-in happens on Microsoft's own infrastructure.
Whether you’re exposed comes down to how your Microsoft 365 environment is configured and licensed. The feature this abuses is on by default, and most environments aren’t yet at the baseline needed to shut it down.
Who’s At Risk
Any organization that runs day-to-day work inside Microsoft 365 — Outlook, Teams, SharePoint, or OneDrive — sits in scope. The exposure is highest where the data is regulated and downtime is expensive.
Industries most exposed
Worth a conversation
What’s Required for Effective Defense
The good news: this is preventable, and it isn't about buying a new product. It's about getting your Microsoft 365 environment to the right configuration and license level. These four close most of the gap.
Make sure you have set a Conditional Access Policy that blocks or tightly limits device-code flow (the door this attack uses) while keeping legitimate business processes working.
Configured properly, DMARC stops attackers impersonating trusted senders. Many organizations have it only half set up, or not at all.
Organizations without modern filtering are the most exposed to the phishing surge already underway. This is a measurable, fast win.
Several of these protections depend on your license level, and most organizations aren't at the baseline yet. Better addressed now than after something goes wrong.
Going Forward: Constant Vigilance
Notes and Sources
- Source: FBI Internet Crime Complaint Center (IC3) public service announcement, PSA260521, May 21, 2026.
- Device-code authentication is a legitimate Microsoft 365 feature. The behavior described here is the abuse of that feature, not a flaw in the protocol itself.
- Configuration and license recommendations are general guidance. The right baseline for your environment depends on your tenant, existing agreements, and operational needs. Nexus IT can confirm specifics for your organization.
Concerned about your exposure to Kali365?
We can help you with a Microsoft 365 risk review. We check your current setup and licensing, tell you exactly where you sit against this threat, and lay out what it takes to close the gaps.