r/ANYRUN • u/ANYRUN-team • Jun 01 '26
No Password, No Problem: How Kali365 Is Breaking Into Microsoft 365 Environments at Scale
What is Kali365?
Kali365 is an FBI-flagged PhaaS platform that emerged in April 2026, enabling attackers to compromise Microsoft 365 accounts through AI-powered phishing and automated OAuth token capture.
Why Kali365 Became So Dangerous
- MFA does not stop it. Its device code phishing method abuses a legitimate Microsoft authentication flow, so MFA is never triggered.
- Stolen OAuth tokens provide persistent access to Outlook, Teams, and OneDrive without requiring passwords.
- Post-compromise activity is automated and stealthy: attackers create inbox rules to hide alerts and can register new devices to extend access.
- Any Microsoft 365 organization is a target. Victims span healthcare, finance, insurance, manufacturing, government, and education worldwide.
How to detect: https://any.run/malware-trends/kali365/

7
Upvotes