FBI Issues Alert on Kali365 Phishing Attacks Targeting OAuth Tokens
The Federal Bureau of Investigation (FBI) has issued an urgent warning regarding a sophisticated wave of phishing attacks utilizing a tool identified as Kali365. This campaign represents a significant shift in how cybercriminals target enterprise environments, moving beyond traditional credential harvesting to compromise Microsoft 365 accounts by bypassing standard multi-factor authentication (MFA) protocols.

How the Kali365 Attack Functions
Unlike conventional phishing scams that attempt to trick users into entering their passwords on a fraudulent login page, Kali365 focuses on the exploitation of OAuth tokens. The attack typically begins with an email designed to mimic communications from trusted cloud-based document sharing services.
When a victim interacts with the message, they are directed to enter a specific code on a legitimate Microsoft-hosted website. This interaction is the trap: by entering the requested code, the user is unknowingly authorizing the attacker’s device to access their Microsoft 365 account. Because this process grants the attacker an access token rather than requiring a password, the attack effectively circumvents traditional MFA, as the system perceives the malicious access as an authorized session.
Mitigation Strategies for IT Security Teams
To defend against these token-stealing tactics, the FBI has provided specific guidance for IT security managers to harden their organizational environments. Recommended defensive measures include:

- Implement Conditional Access Policies: Organizations should configure conditional access policies to block code flow for all users, while providing narrow exceptions only for verified, essential business processes.
- Restrict Authentication Transfers: Security teams should block authentication transfer policies. This prevents users from inadvertently handing over access rights from a secure corporate workstation to an unmanaged mobile device or external system.
The Growing Threat of Modern Phishing
Phishing remains a persistent and evolving challenge for global organizations. As attackers adopt more advanced techniques like OAuth token theft, the reliance on basic password-based MFA is no longer a sufficient defense. Security professionals must remain vigilant, as these tactics are designed specifically to exploit the trust users place in legitimate cloud service authentication flows.
Organizations are encouraged to review their current Microsoft 365 security configurations against the latest guidance from cybersecurity authorities to ensure that token-based access is strictly controlled and monitored for anomalous behavior.
Key Takeaways
- Token Theft vs. Credential Theft: Kali365 bypasses MFA by hijacking OAuth access tokens rather than stealing passwords.
- Deceptive Legitimacy: The attack uses legitimate Microsoft sites to authorize malicious access, making it difficult for users to identify the fraud.
- Proactive Defense: IT managers should prioritize updating conditional access policies and restricting authentication transfers to mitigate the risk.
This report is based on cybersecurity advisories from the FBI. For further information on protecting your organization, please consult the official resources provided by the Internet Crime Complaint Center (IC3).
Worth a look