Kali365 Exploits Microsoft Authentication to Bypass MFA and Compromise US Enterprises
The Kali365 Phishing-as-a-Service (PhaaS) platform has emerged as a significant threat to US enterprises using Microsoft 365. This campaign exploits the legitimate Microsoft device code authentication flow, allowing attackers to bypass multi-factor authentication (MFA) and gain persistent access to enterprise cloud environments without requiring password theft.
Kali365 is not attributed to a single advanced persistent threat (APT) group but is instead a commercialized PhaaS platform distributed via Telegram and underground forums. The service offers AI-generated phishing lures, automated campaign orchestration, real-time dashboards, and robust OAuth token capture capabilities for approximately $250 per month or $2,000 per year.
The attack leverages trusted Microsoft infrastructure, making traditional detection and prevention mechanisms less effective. The FBI has issued public advisories warning of the campaign's ability to bypass MFA and compromise Microsoft 365 environments without password theft. Security researchers have confirmed hundreds of successful intrusions, with attackers leveraging persistent OAuth tokens to access sensitive data, manipulate business processes, and facilitate financial fraud.