← Back to feed
PhishingEmerging1 sourceJul 27, 2026 · 14:00via Flare

Kali365: The Phishing-as-a-Service Operation Expanding Beyond Microsoft 365

Brief

By Assaf Morag, Cybersecurity Researcher

Most phishing kits steal passwords. Kali365 does something more dangerous: it tricks victims into authenticating on a genuine Microsoft page, completing MFA themselves, and unknowingly handing an attacker-controlled session the resulting access tokens. No credentials are intercepted. No fake login page is required. The victim does everything right and still loses control of their identity.

But Kali365 is no longer limited to Microsoft 365. What began as a device-code phishing kit has grown into a subscription phishing platform that impersonates identity providers, cloud services, email platforms, file-sharing tools, and messaging applications across multiple brands and regions.

In May 2026, the FBI described Kali365 as an emerging Phishing-as-a-Service (PhaaS) platform distributed mainly through Telegram.

Read more on Flare