FBI Warns About Kali365: The Tool That Steals Microsoft 365 OAuth Tokens

FBI Avverte su Kali365: Il Tool che Ruba Token OAuth di Microsoft 365

The FBI has issued an official warning about Kali365, a phishing platform engineered to steal Microsoft 365 OAuth tokens. This tool poses a concrete and growing threat to organizations of all sizes. The federal alert comes as attacks exploiting the device code flow see a sharp and accelerating rise.


How Kali365 Works and How It Steals OAuth Tokens

The Device Code Flow Mechanism

Kali365 exploits a legitimate Microsoft authentication mechanism known as the device code authorization flow — a process originally designed for devices without a browser. Threat actors have weaponized it into a precise and highly effective attack vector.

The attack unfolds in clearly defined stages:

  1. The victim receives a phishing email crafted to appear as if it originates from a trusted cloud service or document-sharing platform.
  2. The email instructs the user to enter a code on a legitimate Microsoft website.
  3. That code, however, authorizes the attacker’s device — effectively granting full access to the victim’s Microsoft 365 account.

Why This Attack Is So Dangerous

The critical point is straightforward: MFA does not protect against this scenario. The attacker never steals credentials. Instead, they obtain a valid OAuth token directly, bypassing multi-factor authentication entirely.

What makes it even more insidious is that victims notice nothing unusual. They entered a code on a genuine Microsoft site. They didn’t click a suspicious link. They never typed their password into a fake login page. Everything looks completely normal.


The FBI Alert: Details and Context

A Rapidly Growing Threat

The FBI issued this warning precisely because the phenomenon is expanding fast. Kali365 dramatically lowers the technical barrier to carrying out these attacks — anyone can use it, even without advanced skills.

It is worth noting that no specific threat group has been publicly attributed to this campaign. Federal authorities focused their advisory on the method and the tool itself, with the primary goal of reaching as many organizations as possible before the damage escalates.

In this landscape, the proliferation of platforms like Kali365 represents a genuine paradigm shift. Phishing has evolved. It no longer targets passwords. It targets persistent access to corporate accounts.

Which Organizations Are Most at Risk

No specific sector has been identified as the exclusive target. However, organizations that rely heavily on Microsoft 365 face the greatest exposure — particularly companies with distributed teams and multi-device access environments, where the device code flow is more commonly in use.


How to Defend Your Organization: Recommended Mitigations

Conditional Access Policies and Device Code Flow Blocking

The FBI advisory includes a set of concrete defensive measures. The first and most effective is implementing Conditional Access policies to block the device code flow for users who have no legitimate need for it.

Organizations should also adopt authentication transfer blocking policies, which limit attackers’ ability to move valid tokens onto unauthorized devices.

Additional Steps for Security Teams

The following actions are recommended as priorities:

  • Audit all applications within the corporate environment that currently use the device code flow.
  • Train users to recognize phishing emails that ask them to enter authentication codes.
  • Monitor access logs for anomalous authentication events or logins from unusual geographic locations.
  • Restrict device code flow usage to only those devices and users for whom it is strictly necessary.

User awareness training, however, remains one of the most consistently underestimated defenses. In this type of attack, the trap is nearly invisible. A well-trained user is the first — and often most effective — line of real defense.


Conclusions: A Wake-Up Call for CISOs

The FBI’s warning about Kali365 sends an unambiguous message. Attackers are refining techniques that circumvent traditional defenses, and MFA alone is no longer sufficient. Organizations must urgently revisit their authentication policies.

In this context, IsacChain strongly recommends sharing this intelligence across internal structures. Informing IT teams, security leads, and end users is not optional — it is essential. The threat is real. The response must be immediate.


Sources:

Source: Original article


The rise of tools like Kali365 makes it more urgent than ever for organizations to share threat intelligence in a structured and secure way. IsacChain enables member organizations to exchange indicators of compromise and advisories — such as this FBI alert — within a protected environment backed by blockchain verification, ensuring the integrity and traceability of every piece of shared information. The platform also supports automated NIS2 compliance, helping security teams document the measures they have taken in response to emerging threats like device code phishing. Discover how IsacChain can help your organization at www.isacchain.com