Technology
What is Kali365? FBI warns Telegram-based phishing service targeting Microsoft 365 users – Crypto News
The Federal Bureau of Investigation (FBI) has issued a public warning about a newly identified cybercrime platform called Kali365, a “Phishing-as-a-Service” (PhaaS) toolkit that is being used to target Microsoft 365 users by bypassing multi-factor authentication (MFA) protections.
The platform, first detected in April 2026, is being actively distributed through Telegram channels and is designed to help even low-skilled attackers conduct sophisticated phishing campaigns.
What is Kali365?
Kali365 is a cybercrime subscription service that allows threat actors to carry out automated phishing attacks against cloud-based accounts, particularly Microsoft 365 environments.
According to the FBI, the platform provides attackers with ready-made tools including:
-AI-generated phishing emails and templates
-Automated campaign management systems
-Real-time victim tracking dashboards
-OAuth token capture capabilities
This effectively lowers the technical barrier for cybercriminals, enabling more widespread and scalable attacks.
How the attack works
The FBI outlined a multi-stage process used by attackers leveraging Kali365:
Victims receive emails impersonating trusted cloud services or document-sharing platforms. These emails contain a device code and instructions to visit a legitimate Microsoft login page.
2. User authentication trick
The victim enters the device code on the official Microsoft page, unknowingly authorizing the attacker’s device.
The system captures OAuth access and refresh tokens, giving attackers authenticated access to the victim’s account.
Attackers can then access services such as Outlook, Teams, and OneDrive without needing passwords or triggering MFA again.
The FBI warned that this allows attackers to maintain long-term access to compromised accounts.
Why this attack is dangerous
Unlike traditional phishing, Kali365 exploits OAuth token-based authentication, which means:
-Passwords are not directly stolen
-MFA protections can be bypassed
-Access can persist even after password changes
This makes detection and recovery significantly more difficult for victims and IT teams.
FBI recommendations
The FBI has urged organizations to tighten security controls around Microsoft 365 authentication systems, including:
-Restricting or disabling device code flow authentication
-Implementing strict conditional access policies
-Auditing device code usage for legitimate business needs
-Blocking authentication transfer between devices
-Excluding emergency access accounts from restrictions to prevent lockouts
The agency also advised organizations to proactively monitor login activity and unauthorized session creation.
Reporting cyber incidents
The FBI has asked victims and organizations impacted by Kali365-related attacks to report incidents to the Internet Crime Complaint Center (IC3) at www.ic3.gov.
-Full phishing email details (headers and content)
-Suspicious login data (IP addresses, timestamps, locations)
-Unauthorized device or session activity
Growing threat of Phishing-as-a-Service
The emergence of Kali365 highlights a broader trend in cybercrime: the rise of Phishing-as-a-Service platforms, which package advanced hacking tools into easy-to-use subscription models.
Security experts say this trend is accelerating cyberattacks globally, particularly against cloud-first workplaces that rely heavily on services like Microsoft 365.
The FBI’s warning underscores the need for stronger authentication safeguards and continuous monitoring as attackers increasingly exploit identity-based security weaknesses rather than traditional password theft.
-
others1 week agoShotgun.fun Launches as the First Trading Terminal With 100% Cashback – Crypto News
-
Blockchain1 week agoCardano Crash Exposes ADA’s Deeper Problem, Says Longtime Bull – Crypto News
-
Blockchain1 week agoAnalyst Charts Ethereum Long-Term Roadmap To $16,000 – There’s No Need To Panic – Crypto News
-
Blockchain1 week agoEther Eyes $1,500 Support After 25% Open-Interest Decline – Crypto News
-
De-fi1 week agoLubin-Labeled Wallet Adds 110,000 ETH to Sky Vaults Backing $259M DAI Debt – Crypto News
-
Cryptocurrency1 week agoAnthropic CEO Warns AI Is Getting Too Powerful—While Releasing Powerful AI – Crypto News
-
Business1 week ago
JPMorgan Says Crypto Market H2 Cycle Hinges On Strategy’s Bitcoin Play & CLARITY Act – Crypto News
-
De-fi1 week agoBitMine Buys 126,971 ETH for $207M at $1,630 Average as Prices Hit June Low – Crypto News
-
Technology1 week agoZIGChain integrates Ondo tokenized stocks, ETFs to expand onchain access – Crypto News
-
Blockchain1 week agoBitcoin Holder Accumulation Surged As Metrics Fell To Record Lows – Crypto News
-
De-fi1 week agoPolymarket World Cup Winner Markets Cross $1.8B in Volume as France-Spain Group Stage Opens – Crypto News
-
De-fi1 week agoArthur Hayes Says Bitcoin Cannot Rally Until the AI Bubble Bursts – Crypto News
-
Technology1 week agoRealme P4R 5G launched in India with 8000mAh battery, 144Hz display: Price starts at ₹18,999 – Crypto News
-
De-fi1 week agoBinance Stock Trading Draws 84% of First-Week Volume From Emerging Markets – Crypto News
-
Metaverse6 days agoMythos busters: Why US cyber giants are racing to woo India’s small businesses – Crypto News
-
Business1 week ago
Breaking: Bitcoin Nears $64K As Trump Says Israel, Iran Seek ‘Immediate Ceasefire’ – Crypto News
-
Cryptocurrency1 week ago
Crypto Exchanges Rush to Tap $1 Trillion Pre-IPO Market – Crypto News
-
Cryptocurrency1 week agoOpenAI Wants to Kill the Chatbot It Invented and Turn It Into a Superapp – Crypto News
-
others1 week agoIBM Warns of New ‘Man-in-the-Browser’ Campaign That Locks Victims Inside Fake Bank Screens and Empties Accounts in Real Time – Crypto News
-
others1 week ago
Ethereum isn’t dead’ – Analysts weigh in as ETH rebounds above $1,600 – Crypto News
-
De-fi1 week agoBybit and Kraken Add xStocks SpaceX Tokenized Equity as Pre-IPO Derivatives Race Reaches Four Venues – Crypto News
-
De-fi1 week agoPiggyBank’s LAB Hedge Fails, Cutting USDC Vault NAV by 15% – Crypto News
-
Technology1 week agoApple’s iOS 27 could make your old iPhone feel new again with this one feature – Crypto News
-
Technology1 week agoAI is boosting accuracy for clinicians, Philips North America CEO says – Crypto News
-
Blockchain1 week agoEther Eyes $1,500 Support After 25% Open-Interest Decline – Crypto News
-
Metaverse1 week agoWhat is Claude Fable 5? 7 things to know about Anthropic’s first Mythos model – Crypto News
-
Metaverse1 week agoGoogle Gemini will now do real-time speech translation for your phone calls and online meetings – Crypto News
-
De-fi1 week agoAave Proposes Protocol-Wide Risk Framework After KelpDAO Exploit – Crypto News
-
Technology7 days agoAnthropic CEO Dario Amodei wants AI models regulated like airplanes – Crypto News
-
Technology7 days ago
Citigroup to Launch Tokenized Shares of Anthropic, OpenAI, Ripple – Crypto News
-
Technology7 days ago
Citigroup to Launch Tokenized Shares of Anthropic, OpenAI, Ripple – Crypto News
-
others1 week ago
Breaking: Michael Saylor Announces Buying $101M In Bitcoin For Strategy – Crypto News
-
De-fi1 week ago160 Officials Tell Senate to Pass CLARITY Act as Floor Talks Resume – Crypto News
-
Blockchain1 week agoOpenAI Confidentially Files for US IPO – Crypto News
-
Business1 week ago
Cardano Price Prediction Ahead of June 23 Leios Testnet Launch – Crypto News
-
Technology1 week ago
Wall Street Analysts Expect Fed To Pause Rates At Kevin Warsh’s First FOMC Meeting – Crypto News
-
Business1 week ago
Anthropic Releases Public Mythos Model ‘Claude Fable’ Amid IPO Plans – Crypto News
-
Technology1 week ago
Bitcoin Risks Another Windfall After Elon Musk’s SpaceX IPO, Analysts Say – Crypto News
-
De-fi7 days agoCrypto’s killer app may be selling stocks after its own tokens failed retail – Crypto News
-
Technology4 days agoFormer xAI engineer claims he was fired for raising safety concerns about Grok, told ‘AI will kill us all anyway’ – Crypto News
-
Technology4 days agoFormer xAI engineer claims he was fired for raising safety concerns about Grok, told ‘AI will kill us all anyway’ – Crypto News
-
Cryptocurrency1 week agoShiba Inu (SHIB) Is in Best Possible Recovery State: Analyzing Next Price Targets – Crypto News
-
Cryptocurrency1 week ago
Crypto Exchanges Rush to Tap $1 Trillion Pre-IPO Market – Crypto News
-
Blockchain1 week agoYuga Labs Developers Rescue 68 NFTs From Flooring Exploit – Crypto News
-
others1 week agoSaylor’s Strategy Thunders Back After Last Week’s Bitcoin Sale Rattles Crypto Sector, Acquires $101,000,000 Worth of BTC – Crypto News
-
others1 week agoSaylor’s Strategy Thunders Back After Last Week’s Bitcoin Sale Rattles Crypto Sector, Acquires $101,000,000 Worth of BTC – Crypto News
-
others1 week ago
Strategy Shareholders Approve STRC Semi-Monthly Dividends as Stock Trades Below Par – Crypto News
-
De-fi1 week agoMetaMask Launches Agent Wallet in Early Access, Giving AI Agents Self-Custody Acces – Crypto News
-
Technology1 week ago
Crypto Market This Week: What To Expect From CPI, PPI Data Release? – Crypto News
-
Business1 week ago
Dogecoin Price Prediction Ahead of SpaceX IPO This Week – Crypto News
