<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

FBI-Flagged Phishing Kit Kali365 Expands Beyond Microsoft 365

Kali365, a phishing service bypassing MFA, now targets AWS and Russian platforms, posing a growing cybersecurity threat.
Content Team

Kali365, a phishing-as-a-service platform the FBI warned about on 21 May 2026, has grown far more dangerous. Originally built to bypass MFA on Microsoft 365 accounts, it now impersonates AWS, Okta SSO, Xerox DocuShare, Germany's GMX, and a range of Russian platforms — Mail.ru, Yandex Disk, Odnoklassniki and MAX Messenger.

MAX Messenger is a Russian state-backed app the government has promoted as the country's national messaging service, reporting over 110 million registered users and more than 80 million daily active users as of April 2026.

Arctic Wolf researchers mapped 126 distinct malicious hosts running the same kit between 6 and 27 May. Kali365 abuses OAuth 2.0 device authorization: the attacker starts the login, then tricks the victim into approving it — so MFA is satisfied by the legitimate user and never blocks the theft.

At least 14 device code phishing kits are now circulating, including Tycoon2FA, Venom and CYB3R, and the threat is accelerating.

Defenders should restrict or disable device code flow via Conditional Access where it isn't needed, and block authentication-transfer policies. Arctic Wolf flags panel[.]securehubcloud[.]com as high-confidence C2, recommends blocking *.attachedfile[.]com as a unit, and identifies the kit by its "Preparing your secure document…" page.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo