You have enabled multi-factor authentication. You have trained your staff not to enter passwords on suspicious pages. Your Microsoft 365 accounts are protected.
The FBI has other ideas.
The FBI issued an advisory on 21 May 2026, warning about Kali365, a phishing-as-a-service platform that can take over Microsoft 365 accounts without stealing a password, and without asking the attacker to bypass MFA at all.
What Kali365 Actually Is
Kali365 is a subscription toolkit for cybercriminals, first observed in April 2026 and distributed primarily through Telegram. Subscriptions are reported to start at $250 per month.
For that, attackers get AI-generated phishing lures, automated campaign templates, real-time dashboards for tracking targets, and the ability to capture OAuth tokens from Microsoft 365 environments. It is, in the FBI’s description, a turnkey operation that lowers the barrier to entry for less technically sophisticated attackers.
Security researchers at Arctic Wolf documented hundreds of Kali365 attacks in April alone, with targets spanning manufacturing, education, insurance, financial services, healthcare, and government organisations across North America, Europe, the Middle East, and Africa.
The common factor across those targets: MFA was enabled.
How the Attack Works
Kali365 does not use a fake login page. It does not need one.
The attack abuses device code flow, a legitimate Microsoft authentication feature. If you have ever signed into a streaming service on a smart TV by visiting a website on your phone and typing in a short code, you have used it. The feature exists to let one device borrow an authenticated session from another.
The attack runs as follows:
- The target receives a phishing email impersonating a trusted cloud productivity or document-sharing service
- The email contains a device code and instructions to visit a legitimate Microsoft verification page to enter it
- The target visits the genuine Microsoft domain, sees a valid SSL certificate, and types in the code
- Microsoft hands the attacker an OAuth access token and a refresh token
At that point, the attacker has persistent access to Outlook, Teams, and OneDrive. No password was entered. No MFA prompt was triggered. As far as Microsoft is concerned, the victim authorised the session themselves, on a real Microsoft domain, through a workflow the platform treats as entirely legitimate.
There is no fake website to spot. There is no misspelt domain. The token, once captured, can unlock other connected cloud applications. One click can become a wide-ranging incident.
Why MFA Does Not Stop This
MFA is designed to stop an attacker who has obtained a password from using it to log in. It does not prevent a user from granting access to an attacker through a workflow Microsoft considers legitimate.
In a device code flow attack, the criminal never attempts to log in. They never face an MFA challenge. The victim handles authentication on their behalf, unknowingly, on a genuine Microsoft page.
This is not a flaw in MFA as a concept. It is a gap in how most organisations have deployed it. Enabling MFA addresses credential theft. It does not address token theft through authorised flows.
Steven Campbell, staff threat intelligence researcher at Arctic Wolf, put it plainly: because the attack leverages legitimate Microsoft infrastructure, the activity can appear entirely normal to the victim, which makes it harder to detect after the fact.
What to Do About It
The FBI’s primary recommendation is to restrict or block device code flow entirely, using a conditional access policy in Microsoft Entra ID. Before doing so, organisations should audit existing device code flow usage to identify any legitimate business dependencies that would be disrupted.
Emergency access accounts should be excluded from any blocking policy to avoid accidental lockout.
Beyond that, the FBI recommends:
- Blocking authentication transfer policies that allow users to move authenticated sessions between devices
- Rolling out phishing-resistant MFA, such as hardware security keys, which tie authentication to a physical device and are significantly harder to circumvent
- Reviewing active sessions and connected devices for any authorisations that cannot be explained
If your organisation uses Microsoft 365 and has not reviewed its conditional access policies recently, this is the moment to do it. The Kali365 advisory is not a future risk. The campaign was already running at scale in April.
A Dr Logic Perspective
The broader pattern here is worth noting. Kali365 is one of several phishing-as-a-service platforms targeting Microsoft 365 in 2026. Huntress tracked a parallel campaign, attributed to the Evil Tokens platform, that compromised identities across more than 340 organisations in the US, Canada, Australia, New Zealand, and Germany. Proofpoint documented state-linked actors using the same device code technique from September 2025.
The attack surface is not new. What is new is how accessible the tooling has become. Platforms like Kali365 mean an attacker does not need to understand OAuth token mechanics to exploit them. They need a Telegram account and a subscription fee.
In Dr Logic’s experience, the organisations most exposed to this type of attack are those that enabled MFA and considered the job done. MFA is necessary. It is not sufficient. Conditional access policies, session monitoring, and regular review of authentication flows are the controls that close the gap Kali365 is walking through.
Speak to the Dr Logic team about your Microsoft 365 security posture.



















































