Adversary Intelligence — 2026-05-24

FBI Warns of Kali365 Phishing-as-a-Service Platform Targeting Microsoft 365 at Scale

BLUFDisruption of Kali365 within six months of the FBI's May 21 advisory is unlikely, and the platform's token-sharing model means compromised tenants stay exposed even if the service folds.

The FBI issued a public service announcement on May 21 about Kali365, a phishing-as-a-service platform first observed in April and distributed via Telegram, that captures Microsoft 365 OAuth tokens through device-code flows rather than stealing credentials 1. Victims are directed to a legitimate Microsoft verification page to enter an attacker-supplied code, unknowingly authorizing access; captured tokens then enable persistent entry to Outlook, Teams, and OneDrive without further MFA challenges 12. Arctic Wolf Labs, which obtained access to the Kali365 system, reported the platform charges $250 for 30 days or $2,000 annually and generates AI-driven lures impersonating Adobe, DocuSign, and SharePoint across dozens of languages 23. Arctic Wolf additionally found Kali365 supports adversary-in-the-middle (AitM) session capture alongside device code flows, and enables a full post-compromise workflow including mailbox access, contact harvesting, lateral phishing, and BEC keyword monitoring 23. Captured tokens are stored on the platform and made available to affiliates, allowing reuse by actors who played no part in the original phishing campaign 23.

Analysis
Disruption of Kali365 infrastructure within six months of the FBI's May 21 advisory is unlikely. Moderate confidence reflects documented precedent for PhaaS platforms migrating ahead of legal action, offset by incomplete visibility into any parallel law enforcement operations already targeting the platform. The FBI/IC3 PSA is the sole original source; secondary coverage adds no independent corroboration. FBI advisories of comparable specificity have, in analogous PhaaS cases, preceded platform disruption, and Kali365 may not prove the exception. Captured refresh tokens remain valid until administrators explicitly revoke individual sessions, and enterprise security teams should treat device code flow restriction as a standing control regardless of whether Kali365 survives enforcement.
4 sources
  1. Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens - FBI / Internet Crime Complaint Center (IC3)
  2. FBI warns about fast-growing phishing kit targeting Microsoft 365 users - CyberScoop
  3. FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks - The Record (Recorded Future News)
  4. FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale - The Register

View in full brief →

UNCLASSIFIED // OPEN SOURCE