MFA Won’t Save You From This One: The FBI’s Warning About Kali365

The exterior of a modern building featuring the Microsoft logo and name, with large windows and a sleek, metallic façade under an overcast sky—highlighting enhanced security measures like MFA.

You have enabled multi-factor authentication. You have trained your staff not to enter passwords on suspicious pages. Your Microsoft 365 accounts are protected.

The FBI has other ideas.

The FBI issued an advisory on 21 May 2026, warning about Kali365, a phishing-as-a-service platform that can take over Microsoft 365 accounts without stealing a password, and without asking the attacker to bypass MFA at all.

What Kali365 Actually Is

Kali365 is a subscription toolkit for cybercriminals, first observed in April 2026 and distributed primarily through Telegram. Subscriptions are reported to start at $250 per month.

For that, attackers get AI-generated phishing lures, automated campaign templates, real-time dashboards for tracking targets, and the ability to capture OAuth tokens from Microsoft 365 environments. It is, in the FBI’s description, a turnkey operation that lowers the barrier to entry for less technically sophisticated attackers.

Security researchers at Arctic Wolf documented hundreds of Kali365 attacks in April alone, with targets spanning manufacturing, education, insurance, financial services, healthcare, and government organisations across North America, Europe, the Middle East, and Africa.

The common factor across those targets: MFA was enabled.

How the Attack Works

Kali365 does not use a fake login page. It does not need one.

The attack abuses device code flow, a legitimate Microsoft authentication feature. If you have ever signed into a streaming service on a smart TV by visiting a website on your phone and typing in a short code, you have used it. The feature exists to let one device borrow an authenticated session from another.

The attack runs as follows:

  1. The target receives a phishing email impersonating a trusted cloud productivity or document-sharing service
  2. The email contains a device code and instructions to visit a legitimate Microsoft verification page to enter it
  3. The target visits the genuine Microsoft domain, sees a valid SSL certificate, and types in the code
  4. Microsoft hands the attacker an OAuth access token and a refresh token

At that point, the attacker has persistent access to Outlook, Teams, and OneDrive. No password was entered. No MFA prompt was triggered. As far as Microsoft is concerned, the victim authorised the session themselves, on a real Microsoft domain, through a workflow the platform treats as entirely legitimate.

There is no fake website to spot. There is no misspelt domain. The token, once captured, can unlock other connected cloud applications. One click can become a wide-ranging incident.

Why MFA Does Not Stop This

MFA is designed to stop an attacker who has obtained a password from using it to log in. It does not prevent a user from granting access to an attacker through a workflow Microsoft considers legitimate.

In a device code flow attack, the criminal never attempts to log in. They never face an MFA challenge. The victim handles authentication on their behalf, unknowingly, on a genuine Microsoft page.

This is not a flaw in MFA as a concept. It is a gap in how most organisations have deployed it. Enabling MFA addresses credential theft. It does not address token theft through authorised flows.

Steven Campbell, staff threat intelligence researcher at Arctic Wolf, put it plainly: because the attack leverages legitimate Microsoft infrastructure, the activity can appear entirely normal to the victim, which makes it harder to detect after the fact.

What to Do About It

The FBI’s primary recommendation is to restrict or block device code flow entirely, using a conditional access policy in Microsoft Entra ID. Before doing so, organisations should audit existing device code flow usage to identify any legitimate business dependencies that would be disrupted.

Emergency access accounts should be excluded from any blocking policy to avoid accidental lockout.

Beyond that, the FBI recommends:

  • Blocking authentication transfer policies that allow users to move authenticated sessions between devices
  • Rolling out phishing-resistant MFA, such as hardware security keys, which tie authentication to a physical device and are significantly harder to circumvent
  • Reviewing active sessions and connected devices for any authorisations that cannot be explained

If your organisation uses Microsoft 365 and has not reviewed its conditional access policies recently, this is the moment to do it. The Kali365 advisory is not a future risk. The campaign was already running at scale in April.

A Dr Logic Perspective

The broader pattern here is worth noting. Kali365 is one of several phishing-as-a-service platforms targeting Microsoft 365 in 2026. Huntress tracked a parallel campaign, attributed to the Evil Tokens platform, that compromised identities across more than 340 organisations in the US, Canada, Australia, New Zealand, and Germany. Proofpoint documented state-linked actors using the same device code technique from September 2025.

The attack surface is not new. What is new is how accessible the tooling has become. Platforms like Kali365 mean an attacker does not need to understand OAuth token mechanics to exploit them. They need a Telegram account and a subscription fee.

In Dr Logic’s experience, the organisations most exposed to this type of attack are those that enabled MFA and considered the job done. MFA is necessary. It is not sufficient. Conditional access policies, session monitoring, and regular review of authentication flows are the controls that close the gap Kali365 is walking through.

Speak to the Dr Logic team about your Microsoft 365 security posture.

DR Logic

Dr Logic is an Apple Premium Technical Partner supporting businesses across London and the UK. Founded in 2003, the team of 34 Apple-certified engineers and consultants helps organisations get the most from their technology through proactive IT support, cyber security, and strategic IT planning.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.