{"id":687267,"date":"2026-05-22T12:07:13","date_gmt":"2026-05-22T12:07:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/687267\/"},"modified":"2026-05-22T12:07:13","modified_gmt":"2026-05-22T12:07:13","slug":"microsoft-365-users-targeted-by-new-phishing-threat-that-bypasses-mfa","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/687267\/","title":{"rendered":"Microsoft 365 users targeted by new phishing threat that bypasses MFA"},"content":{"rendered":"<p>Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/05\/phishing_650.webp\" class=\"aligncenter\" alt=\"Kali365 Microsoft 365 phishing\" title=\"Phishing\"\/><\/p>\n<p>First observed in April 2026, Kali365 has been distributed through <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/26\/telegram-job-scams-activity\/\" rel=\"nofollow noopener\" target=\"_blank\">Telegram<\/a>, allowing cybercriminals to obtain Microsoft 365 access tokens and bypass MFA without stealing user credentials.<\/p>\n<p>\u201cKali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual\/entity tracking dashboards, and OAuth token capture capabilities,\u201d the FBI said.<\/p>\n<p>This type of attack is known as device code phishing, where attackers trick users into logging into their accounts through a legitimate authentication flow and then steal their access and refresh tokens.<\/p>\n<p>How the attack works<\/p>\n<p>The attack starts with a phishing email that impersonates trusted cloud or document-sharing services and includes a device code with instructions to visit a legitimate Microsoft verification page. <\/p>\n<p>After the victim enters the code, they unknowingly authorize the attacker\u2019s device. <\/p>\n<p>The attacker then captures <a href=\"https:\/\/www.helpnetsecurity.com\/2025\/10\/22\/attackers-turn-trusted-oauth-apps-into-cloud-backdoors\/\" rel=\"nofollow noopener\" target=\"_blank\">OAuth access<\/a> and refresh tokens, allowing continued access to Microsoft 365 services such as Outlook, Teams, and OneDrive without requiring a password or additional MFA prompts.<\/p>\n<p>In its announcement, the FBI outlined several <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260521\" target=\"_blank\" rel=\"nofollow noopener\">tips<\/a> users and organizations can follow to protect themselves from device code phishing attacks.<\/p>\n<p>Telegram-based phishing services<\/p>\n<p>Researchers also recently identified <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/03\/31\/eviltokens-phishing-microsoft-365\/\" rel=\"nofollow noopener\" target=\"_blank\">EvilTokens<\/a>, another PhaaS platform sold through Telegram. <\/p>\n<p>The service gives less-experienced attackers ready-made tools for phishing campaigns, including fake login pages, Microsoft API automation, and AI-generated emails. <\/p>\n<p>It also comes with templates built around common business notifications, such as SharePoint access requests, password expiration messages, and shared document alerts.<\/p>\n<p>According to Barracuda Networks, the <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/01\/08\/barracuda-phishing-kit-techniques\/\" rel=\"nofollow noopener\" target=\"_blank\">most common phishing themes<\/a> in 2025 pushed users toward clicking links, scanning QR codes, opening attachments, or handing over personal information.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is&hellip;\n","protected":false},"author":2,"featured_media":687268,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,13933,7810,2577,11965,53555,105],"class_list":["post-687267","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-cybercrime","tag-fbi","tag-microsoft","tag-microsoft-365","tag-phishing","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/687267","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=687267"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/687267\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/687268"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=687267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=687267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=687267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}