Microsoft 365Incident TeardownsNews

Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365 access tokens and bypass multi-factor authentication without stealing passwords, according to Help Net Security.

What was reported

  • Kali365 is distributed through Telegram as a subscription service.
  • It focuses on capturing Microsoft 365 tokens, giving attackers access to mailboxes and data without needing the user's credentials.
  • Like EvilTokens and other recent kits, it reflects the commercialization of token theft techniques — including device code phishing and adversary-in-the-middle approaches — that were once limited to skilled or state-sponsored actors.
  • Other tooling abusing Microsoft's device code flow, such as DEBULL, was reported later in 2026.

Why it matters

A few years ago, defeating MFA required custom infrastructure and skill. In 2026, it's a product with customer support. That shifts the defensive baseline:

  • Standard MFA (push approvals, codes) is no longer sufficient protection for email on its own.
  • Token-focused defenses matter: binding tokens to devices, requiring compliant devices, and detecting anomalous token use.
  • Volume increases: more criminals can run campaigns.

What to do now

  • Block device code flow for users who don't need it.
  • Require phishing-resistant MFA (passkeys, FIDO2) — at minimum for administrators, executives and finance.
  • Require compliant or hybrid-joined devices for Microsoft 365 access where feasible.
  • Enable token protection for supported apps and users.
  • Monitor for anomalous token and session activity with Entra ID Protection and Defender XDR.
  • Brief employees on code-based and session-stealing phishing.

Sources

  1. Source
kali365 phishingKali365 PhaaS2026

More on this story