{"id":57388,"date":"2026-05-27T07:48:18","date_gmt":"2026-05-27T07:48:18","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=57388"},"modified":"2026-05-27T07:48:18","modified_gmt":"2026-05-27T07:48:18","slug":"kali365-phishing-kit-bypasses-mfa-and-steals-microsoft-logins","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=57388","title":{"rendered":"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-27T12:05:07&#8243;,&#8221;description&#8221;:&#8221;When the Federal Bureau of Investigation (FBI) publishes a dedicated public service announcement about a new phishing kit, it\u2019s worth paying attention to.\\n\\nThe agency is now warning about \u201cKali365,\u201d a phishing\u2011as\u2011a\u2011service (PhaaS) platform that helps even low\u2011skilled attackers hijack Microsoft 365 accounts by stealing access tokens instead of passwords.\\n\\nAlthough early reporting focuses on attacks against organizations, the underlying technique works just as easily against individual Microsoft 365 users who are tricked into entering a short code on a real Microsoft website. In other words, this is not just a business or IT department problem. It could affect anyone with an Outlook, OneDrive, or Microsoft 365 subscription.\\n\\nFor cybercriminals using the kit, it offers three clear advantages:\\n\\n  * It bypasses multi\u2011factor authentication (MFA) by stealing access tokens, so extra codes or apps no longer help once the token is compromised.\\n  * Kali365 provides ongoing access. The attackers can keep using Outlook, Teams, and OneDrive without repeatedly logging in, as long as the stolen refresh token remains valid.\\n  * Little technical skill needed. Cybercriminals can subscribe to Kali365 and immediately run token\u2011stealing campaigns at scale.\\n\\n\\n\\n## What does the attack look like?\\n\\nVictims receive a phishing message that looks like it comes from a cloud service or collaboration tool, such as a document\u2011sharing notification or Teams invite. The message includes a short \u201cdevice code\u201d and instructions like: \u201cGo to Microsoft\u2019s verification page and enter this code to view the document.\u201d\\n\\n* * *\\n\\n![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/phishing-scam-protection-icon-0B73D5.svg?w=1024)\\n\\n### Scam or legit? Scam Guard knows.\\n\\nTRY IT NOW\\n\\n* * *\\n\\nUnlike many phishing emails, this one sends you to a real Microsoft URL used for device sign\u2011in flows. To the user, the page looks familiar and completely legitimate, which lowers suspicion.\\n\\nVictims then see the standard Microsoft sign\u2011in and consent screens and may think they are simply completing a normal security check. They never see a fake page, never type their password into a suspicious form, and may even see their organization\u2019s branding.\\n\\nBut what they don\u2019t realize is that they have handed access to the attacker.\\n\\nOnce the victim approves the request, the attacker\u2019s device receives OAuth access and refresh tokens tied to the victim\u2019s Microsoft 365 account. These tokens are what Microsoft uses to \u201cremember\u201d that you have already logged in, and they can be reused to access Outlook, OneDrive, Teams, and other Microsoft services without entering a password again.\\n\\nWith valid refresh tokens, attackers can maintain long\u2011term access until the tokens are revoked or expire, often blending in with normal account activity.\\n\\nThat access can allow cybercriminals to:\\n\\n  * Read Outlook emails, including password reset messages\\n  * Access files stored in OneDrive or SharePoint\\n  * Send phishing emails to coworkers, customers, friends, or family from the victim&#8217;s account\\n\\n\\n\\n## How to protect yourself\\n\\nOnce in Outlook, attackers can not only read your messages but also send convincing new ones from your address, using your identity to compromise additional accounts and contacts.\\n\\nSome tips to steer clear of this one:\\n\\n  * Never enter a code at a Microsoft login page just because an email or message tells you to. You should only do this when you initiated the sign\u2011in yourself on your own device.\\n  * Slow down and read the prompts. Rushing through login approvals without reading them carefully can be costly.\\n  * Be suspicious of unexpected document shares, Teams invites, or login requests, even if they use legitimate Microsoft pages.\\n  * Review which devices are logged in under your account at https:\/\/account.microsoft.com\/devices\/. If you see unfamiliar devices or sign\u2011ins, remove them, change your Microsoft account password, and review your security settings.\\n\\n\\n\\nPro tip: Malwarebytes Scam Guard can help you figure out if a message is a scam.\\n\\n* * *\\n\\n****Let &#8216;s face it, an incognito window can only do so much.**   \\n   \\n**Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.&#8221;,&#8221;published&#8221;:&#8221;2026-05-27T11:41:54&#8243;,&#8221;modified&#8221;:&#8221;2026-05-27T11:41:54&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Kali365 phishing kit bypasses MFA and steals Microsoft logins&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/scams\/2026\/05\/kali365-phishing-kit-bypasses-mfa-and-steals-microsoft-logins&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-27T12:05:07&#8243;,&#8221;description&#8221;:&#8221;When the Federal Bureau of Investigation (FBI) publishes a dedicated public service announcement about a new phishing kit, it\u2019s worth paying attention to.\\n\\nThe agency is&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-57388","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=57388\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-05-27T12:05:07&#8243;,&#8221;description&#8221;:&#8221;When the Federal Bureau of Investigation (FBI) publishes a dedicated public service announcement about a new phishing kit, it\u2019s worth paying attention to.nnThe agency is...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=57388\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-27T07:48:18+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A\",\"datePublished\":\"2026-05-27T07:48:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388\"},\"wordCount\":845,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=57388#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388\",\"name\":\"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-05-27T07:48:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=57388\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=57388#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=57388","og_locale":"en_US","og_type":"article","og_title":"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-05-27T12:05:07&#8243;,&#8221;description&#8221;:&#8221;When the Federal Bureau of Investigation (FBI) publishes a dedicated public service announcement about a new phishing kit, it\u2019s worth paying attention to.nnThe agency is...","og_url":"https:\/\/zero.redgem.net\/?p=57388","og_site_name":"zero redgem","article_published_time":"2026-05-27T07:48:18+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=57388#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=57388"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A","datePublished":"2026-05-27T07:48:18+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=57388"},"wordCount":845,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=57388#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=57388","url":"https:\/\/zero.redgem.net\/?p=57388","name":"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-05-27T07:48:18+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=57388#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=57388"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=57388#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Kali365 phishing kit bypasses MFA and steals Microsoft logins_MALWAREBYTES:CCB440196E8F4C999E5A1A5D3059D05A"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/57388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=57388"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/57388\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=57388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=57388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=57388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}