FBI Warns of Kali Phishing Scam Hitting Microsoft OAuth Tokens – Warns “Kali365 Lowers Barrier of Entry, Giving Less Tech Attackers Access to AI-Generated Phishing Lures”
FBI flags Kali365, a phishing kit sold on Telegram that steals Microsoft 365 OAuth tokens and bypasses MFA Victims are tricked into entering device codes on legitimate Microsoft sites, unknowingly authorizing the hacker’s access to Outlook, Teams and OneDrive Remediation steps include restricting device code flow, enforcing conditional access policies, auditing usage, and blocking authentication […]









