WASHINGTON — The FBI issued a Public Safety Announcement on May 21 warning about a new phishing tool targeting Microsoft 365 accounts. The tool, called Kali365, enables cyberattackers to bypass multi-factor authentication and gain persistent access to user accounts.
Kali365 was first spotted in April and is primarily distributed through Telegram. Cyberattackers using the tool send fraudulent emails that appear authentic and direct recipients to a legitimate Microsoft verification page where they unknowingly enter a device code. Entering the code grants attackers access and refresh tokens, allowing them to use Microsoft 365 services such as Outlook, Teams, and OneDrive without needing a password or additional authentication.
The FBI stated that through the Kali365 platform subscription, cyber threat actors can capture OAuth tokens and gain persistent access to targeted individuals' or entities' Microsoft 365 environments. The FBI said the platform lowers the barrier of entry for less-skilled hackers by providing AI-generated phishing lures and automated campaign templates. Cybersecurity software company Bitdefender described Kali365 as a “subscription service for scammers.” Microsoft stated it is “actively working to disrupt the cybercriminal ecosystems behind phishing-as-a-service and account takeover activity to protect our customers.” The FBI and Microsoft recommend verifying the sender’s email address for typos and avoiding unfamiliar links or attachments, instead navigating directly to official websites.
The FBI encourages users to report unauthorized devices, active sessions, suspicious logins, or phishing emails to the Internet Crime Complaint Center. Users are also urged to report phishing messages to the Federal Trade Commission or forward them to phishing-report@us-cert.gov. The FBI suggests restricting device code flow to limit or block device authentication codes, which prevents attackers from obtaining the tokens needed to bypass passwords.
forum Comments (0)
No comments yet. Be the first to comment.