The FBI has warned that Kali365, a phishing-as-a-service platform sold primarily through Telegram, is targeting Microsoft 365 users by abusing Microsoft's legitimate device code authentication flow to steal OAuth access and refresh tokens. First observed in April 2026, the service gives low-skill criminals AI-generated phishing lures, automated campaign templates, token-capture features, and victim tracking dashboards. Victims are lured with emails impersonating SharePoint, OneDrive, Microsoft 365 voicemail, DocuSign, Adobe Acrobat Sign, and other trusted cloud or document-sharing services, then sent to a real Microsoft verification page where they enter an attacker-supplied device code.
Once the code is entered, the attacker can hijack the session and gain persistent access to Outlook, Teams, and OneDrive without needing the victim's password or additional MFA prompts, enabling data theft and business email compromise. The FBI alert, tracked as I-052126-PSA, urges organizations to restrict or block device code flows where possible, audit legitimate dependencies on that authentication method, enforce conditional access policies, monitor unusual sign-ins and token use, preserve emergency access accounts, block authentication transfer policies, and report incidents to IC3 while retaining phishing emails, login records, and evidence of unauthorized devices or sessions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
LevelBlue reported that Tycoon2FA, previously known as an adversary-in-the-middle phishing kit, was now being used for Microsoft device code phishing. The finding indicated device code phishing had spread beyond dedicated kits like Kali365 and become a capability used across more mature phishing ecosystems.
Hornetsecurity reported a newer Kali365-style device-code phishing variant observed on 2026-06-06. The variant used different lure themes but preserved the same OAuth token-theft technique against Microsoft 365 users via attacker-supplied device codes.
A follow-up report attributed to Arctic Wolf said the Kali365 operator broadened both infrastructure and targeting scope beyond earlier Microsoft 365-focused activity. The expanded operation was described as spanning Microsoft Outlook, Okta, Xerox DocuShare, and other services under a broader 'MAX Takeover' campaign.
The FBI published IC3 Alert PSA260521 warning that Kali365 was hijacking Microsoft 365 access tokens through device code phishing. The advisory described the platform's capabilities, noted its use by lower-skill actors, and recommended mitigations such as restricting device code flow, enforcing conditional access, and preserving evidence for IC3 reporting.
Huntress investigated a surge of Microsoft device code authentication events beginning on 2026-05-18 and attributed the activity to the Kali365/Octopi365 phishing-as-a-service ecosystem. The report disclosed E1, E2, and E3 panel variants plus companion tools called OctoLink Live and OctoLink Sender that help operators turn stolen tokens into live sessions and large-scale phishing activity.
Kali365, a phishing-as-a-service platform sold primarily via Telegram, was first observed targeting Microsoft 365 users in April 2026. The service used device code phishing to steal OAuth access and refresh tokens, enabling attackers to bypass MFA and maintain access to Outlook, Teams, and OneDrive.
ESET reported that the EvilTokens phishing-as-a-service kit had been observed in active attacks since at least February 2026. The kit abuses Microsoft's OAuth 2.0 device authorization grant flow to compromise Microsoft 365 accounts by tricking victims into entering attacker-generated device codes on the legitimate microsoft.com/devicelogin page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
26 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourceonlinethreatalerts.com
Open sourcehelpnetsecurity.com
Open sourceic3.gov
Open sourceblog.sekoia.io
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.