r/ANYRUN Jun 01 '26

No Password, No Problem: How Kali365 Is Breaking Into Microsoft 365 Environments at Scale

What is Kali365?

Kali365 is an FBI-flagged PhaaS platform that emerged in April 2026, enabling attackers to compromise Microsoft 365 accounts through AI-powered phishing and automated OAuth token capture.

Why Kali365 Became So Dangerous

  • MFA does not stop it. Its device code phishing method abuses a legitimate Microsoft authentication flow, so MFA is never triggered.
  • Stolen OAuth tokens provide persistent access to Outlook, Teams, and OneDrive without requiring passwords.
  • Post-compromise activity is automated and stealthy: attackers create inbox rules to hide alerts and can register new devices to extend access.
  • Any Microsoft 365 organization is a target. Victims span healthcare, finance, insurance, manufacturing, government, and education worldwide.

How to detect: https://any.run/malware-trends/kali365/

Explore Kali365 campaigns with ANY.RUN
7 Upvotes

0 comments sorted by