Microsoft 365 Hacked? New Phishing Threat Bypasses MFA! (Kali365 Explained) (2026)

Microsoft 365 users are facing a new and insidious threat, one that's not just about stealing passwords or credentials. It's about tricking users into handing over their access tokens, effectively bypassing Multi-Factor Authentication (MFA) and granting attackers unrestricted access to sensitive data and services. This emerging phishing threat, known as device code phishing, is facilitated by a Phishing-as-a-Service (PhaaS) platform called Kali365, which is being distributed through Telegram. Personally, I find this particularly fascinating because it highlights the evolving nature of cyber threats and the increasing sophistication of phishing techniques. What makes this especially concerning is that it lowers the barrier of entry for attackers, providing them with AI-generated phishing lures, automated campaign templates, and real-time tracking dashboards, all accessible through Telegram. This means that even less-technical attackers can launch sophisticated phishing campaigns, targeting individuals and entities with precision. From my perspective, this attack is a stark reminder of the importance of user education and the need for organizations to stay vigilant against evolving threats. It also underscores the critical role of MFA in protecting against such attacks. The attack works by tricking users into logging into their accounts through a legitimate authentication flow. The phishing email impersonates trusted cloud or document-sharing services and includes a device code with instructions to visit a legitimate Microsoft verification page. After the victim enters the code, they unknowingly authorize the attacker's device. The attacker then captures OAuth access and refresh tokens, allowing continued access to Microsoft 365 services such as Outlook, Teams, and OneDrive without requiring a password or additional MFA prompts. What many people don't realize is that this type of attack doesn't just steal credentials; it grants the attacker long-term, unrestricted access to the victim's accounts. This raises a deeper question: how can we better protect users against such sophisticated phishing attacks? One thing that immediately stands out is the role of Telegram in facilitating these threats. Researchers have also identified another PhaaS platform, EvilTokens, sold through Telegram. This service provides ready-made tools for phishing campaigns, including fake login pages, Microsoft API automation, and AI-generated emails. It also comes with templates built around common business notifications, such as SharePoint access requests, password expiration messages, and shared document alerts. This highlights the need for organizations to monitor their networks for suspicious activity and to educate their users about the risks of clicking on unknown links or downloading attachments. In my opinion, the key to mitigating these threats lies in a multi-layered approach. This includes implementing robust MFA, educating users about phishing tactics, and continuously monitoring networks for suspicious activity. Additionally, organizations should consider using advanced threat detection and response solutions that can identify and mitigate such attacks in real-time. Looking ahead, I believe that the battle against phishing threats will continue to evolve. As attackers become more sophisticated, so too must our defenses. This may involve the development of more advanced AI-driven threat detection systems, the integration of machine learning into security solutions, and the adoption of zero-trust security models. In conclusion, the threat of device code phishing and the role of PhaaS platforms like Kali365 and EvilTokens highlights the ongoing battle between attackers and defenders in the digital realm. It's a battle that requires constant vigilance, innovation, and collaboration. As an expert, I believe that by staying informed, implementing robust security measures, and fostering a culture of cybersecurity awareness, we can better protect ourselves and our organizations from these evolving threats.

Microsoft 365 Hacked? New Phishing Threat Bypasses MFA! (Kali365 Explained) (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 5877

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.