Kali365: a Microsoft 365 attack that doesn’t need your password.

The FBI has recently warned the public about a phishing platform that targets Microsoft 365 users. It doesn't steal passwords, and it doesn't trip MFA. Here is how it works, why standard defenses miss it, and how you can protect yourself and your company.
Share this post
In this article
01

What is Kali365

Kali365 is a phishing-as-a-service platform built to target Microsoft 365 users. It hands attackers a ready-made kit: AI-generated lures, campaign templates, tracking dashboards, and a method to capture Microsoft 365 access tokens. The FBI issued a public warning after it was first seen in April 2026.

Kali365 does not always need to steal a password to create risk. Attackers can trick a user into authorizing access through Microsoft's own legitimate sign-in flow, then walk away with a valid access token. With that token, they can reach Microsoft 365 services even when multi-factor authentication is switched on.

Because the kit is a low-cost subscription distributed through Telegram, even low-skill attackers can run polished campaigns at scale. This is not a reason to panic. It is a reason to confirm a handful of settings in your environment are configured the way you'd expect.

Summary

Modern phishing is no longer just about stealing passwords. It is about stealing access. Kali365 captures a session token directly, so the usual warning signs – a wrong password, a missed MFA prompt – never fire.

02

Attack Methodology

Most of the steps below happen on real Microsoft infrastructure, which is exactly why a careful person can still be caught.

1
A convincing lure arrives

An employee gets an email that looks like it's from a trusted service — DocuSign, SharePoint, OneDrive, or Adobe. The content is often AI-generated, so it reads cleanly and on-brand.

2
It asks for a short code on a real Microsoft page

The email directs the user to a genuine Microsoft sign-in page and asks them to enter a short verification code. The web address is real, so there's no fake URL for a careful person to catch.

3
Entering the code authorizes the attacker

The moment the user enters that code, they approve a sign-in the attacker started moments earlier. Microsoft hands back a valid access token to the attacker, not the user.

4
The attacker is now authorized and stays autorized

With that token, the attacker has working access to Outlook, Teams, OneDrive, and SharePoint. No password was stolen, no MFA prompt was failed, and the access tends to persist until the token is revoked.

03

Why MFA Doesn’t Prevent It

Most organizations treat MFA as the finish line. Attacks like Kali365 show that MFA is critical, but it is not the whole picture.

The technique abuses device-code authentication, a legitimate Microsoft 365 feature. Think of signing into a streaming app on a smart TV: the screen shows a code, you enter it on your phone, and the TV is logged in. Kali365 simply turns that flow against the user. The Microsoft login page can be real, the MFA prompt can be real, and the user can still unknowingly authorize the attacker's session.

Team Assumptions
  • "We have MFA, so accounts are protected."
  • "Our spam filter would catch a phishing email."
  • "A fake login page would have a suspicious web address."
Reality
  • The token is captured after a real MFA prompt, so MFA never blocks it.
  • The lure links to a genuine Microsoft page, so there's nothing for a filter to flag as suspicious.
  • The web address is real, because the sign-in happens on Microsoft's own infrastructure.
What’s Your Exposure?

Whether you’re exposed comes down to how your Microsoft 365 environment is configured and licensed. The feature this abuses is on by default, and most environments aren’t yet at the baseline needed to shut it down.

04

Who’s At Risk

Any organization that runs day-to-day work inside Microsoft 365 — Outlook, Teams, SharePoint, or OneDrive — sits in scope. The exposure is highest where the data is regulated and downtime is expensive.

Industries most exposed

Healthcare Finance Legal Manufacturing Professional services

Worth a conversation

IT & Security leaders CIO / COO Compliance Operations
05

What’s Required for Effective Defense

The good news: this is preventable, and it isn't about buying a new product. It's about getting your Microsoft 365 environment to the right configuration and license level. These four close most of the gap.

Restrict the Abused Feature
Conditional access

Make sure you have set a Conditional Access Policy that blocks or tightly limits device-code flow (the door this attack uses) while keeping legitimate business processes working.

Lock down DMARC
Email authentication

Configured properly, DMARC stops attackers impersonating trusted senders. Many organizations have it only half set up, or not at all.

Filter in front of mailboxes
Advanced mail filtering

Organizations without modern filtering are the most exposed to the phishing surge already underway. This is a measurable, fast win.

Get to the right license tier
The most common gap

Several of these protections depend on your license level, and most organizations aren't at the baseline yet. Better addressed now than after something goes wrong.

Going Forward: Constant Vigilance
Monitor active Microsoft 365 sessions and suspicious sign-ins so an unexpected token shows up quickly.
Review OAuth app permissions and consent settings to limit what a captured session can reach.
Have a process to revoke suspicious tokens fast so access can be cut the moment something looks wrong.
Train users not to enter device codes from unexpected emails — the single behavior that stops this at the source.
06

Notes and Sources

  1. Source: FBI Internet Crime Complaint Center (IC3) public service announcement, PSA260521, May 21, 2026.
  2. Device-code authentication is a legitimate Microsoft 365 feature. The behavior described here is the abuse of that feature, not a flaw in the protocol itself.
  3. Configuration and license recommendations are general guidance. The right baseline for your environment depends on your tenant, existing agreements, and operational needs. Nexus IT can confirm specifics for your organization.

Concerned about your exposure to Kali365?

We can help you with a Microsoft 365 risk review. We check your current setup and licensing, tell you exactly where you sit against this threat, and lay out what it takes to close the gaps.