Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA) — Threadlinqs Intelligence
As of 2026-05-30, Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA) is a high-severity phishing threat attributed to Kali365 PhaaS operators (Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0560 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Kali365 PhaaS operators · Unknown (criminal PhaaS; Russian-aligned APT29 observed as customer) · FINANCIAL
Kali365 is a Phishing-as-a-Service (PhaaS) platform, first observed in April 2026 and warned about by FBI PSA I-052126-PSA on 2026-05-21, that abuses Microsoft's legitimate OAuth 2.0 device
Kali365 is a turnkey Phishing-as-a-Service (PhaaS) offering that surfaced in underground Telegram channels around April 2026 and was elevated to a FBI Public Service Announcement (I-052126-PSA) on 2026-05-21 after observed exploitation against U.S. enterprise Microsoft 365 tenants in healthcare, financial services, legal, and managed-services sectors. Unlike traditional adversary-in-the-middle (AiTM) kits such as Tycoon2FA or EvilProxy, Kali365 does not proxy victim credentials; instead it exploits the legitimate Microsoft identity platform device authorization grant (https://login.microsoftonline.com/{tenant}/oauth2/v2.0/devicecode), turning a sanctioned protocol into a no-credential-theft phishing primitive.
The operator workflow is automated end-to-end. From a Kali365 web panel (hosted on bullet-proof infrastructure behind Cloudflare and rotating .top / .shop / .cfd domains), the attacker selects an AI-generated lure (Teams meeting invite, IT helpdesk re-authentication notice, document share, vendor invoice). Kali365 backend calls the Microsoft OAuth devicecode endpoint with first-party client_ids commonly trusted in enterprises — most frequently 04b07795-8ddb-461a-bbee-02f9e1bf7b46 (Azure CLI), d3590ed6-52b3-4102-aeff-aad2292ab01c (Microsoft Office), 1950a258-227b-4e31-a9cf-717495945fc2 (Azure PowerShell), and 14d82eec-204b-4c2f-b7e8-296a70dab67e (Microsoft Graph PowerShell) — and requests scopes such as offline_access, openid, profile, Mail.ReadWrite, Files.ReadWrite.All, User.Read, Directory.Read.All, and Sites.Read.All. Microsoft returns a short-lived (~15 minute) user_code and a verification_uri (microsoft.com/devicelogin or microsoft.com/deviceauth). Kali365 then renders these inside an AI-tailored email body and dispatches the campaign via compromised SendGrid, Brevo and Mailgun accounts (and increasingly through trusted compromised tenants to gain inbox-placement reputation).
When the targeted user clicks the link, they land on the real Microsoft device login page — there is no fake page. The victim enters the attacker-supplied code, completes their normal MFA challenge (FIDO2, Microsoft Authenticator, TOTP, or text), and consents — at which point Microsoft issues the access_token and refresh_token to the attacker's polling backend. Because the user performed full MFA on Microsoft's real surface, the tenant Sign-in logs record a successful interactive sign-in with strongAuthentication = true, often from a residential-proxy IP geolocated near the victim. The refresh_token is long-lived (90 days rolling for most tenants without Conditional Access token-lifetime policies) and can be silently refreshed to maintain persistence.
With tokens in hand, Kali365 operators run automated post-exploitation playbooks: enumerate the mailbox via Graph /me/messages, harvest contacts and global address list, create hidden Outlook inbox rules to forward or delete messages matching keywords like 'invoice', 'wire', 'payroll', register a new Authenticator device through MySecurityInfo to seed long-term persistence even after a password reset, exfiltrate OneDrive and SharePoint documents via batched Graph requests, send internal BEC lures from the victim mailbox, and pivot to Teams chats. Higher-tier Kali365 subscribers receive a 'Tenant Recon' module that maps the directory through Graph /organization and /users to identify Global Administrators and conditional-access policies before targeting.
Kali365 is sold on a tiered subscription via Telegram bot @kali365_support_bot with 'Starter' ($300/week), 'Pro' ($1,200/month) and 'Enterprise' ($3,500/month) tiers that unlock concurrent campaigns, AI lure variants, residential proxy egress, and 24/7 operator chat. The platform shares operators and infrastructure overlap with the older EvilTokens kit referenced in adjacent reporting; Microsoft Threat Intelligence and Volexity have linked some Kali365 campaigns to financially-motivated cluster Storm-1755 and to opportunistic abuse by Russian-a
Weaknesses (CWE)
CWE-287, CWE-294, CWE-522, CWE-345, CWE-451, CWE-770
Target sectors: healthcare, financial-services, legal, managed-service-providers, government, education, technology, manufacturing
Target regions: North America, Europe, Australia, United Kingdom
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583.003, T1583.006, T1586, T1585.002, T1588.002, T1587.001, T1608.005, T1566, T1566.002