Kali365 Microsoft 365 device-code phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypass. The operation uses phishing emails that push victims to Microsoft's device code portal, where they unknowingly authorize attacker access. The campaign matters because successful logins can expose mailboxes, cloud applications, and follow-on infrastructure used to hide activity and steal data. It was observed in April 2026 and reflects a broader criminal phishing service ecosystem.
Related Happenings
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Timeline
-
25.05.2026 15:45 3 articles · 1mo ago
Kali365 Microsoft 365 device-code phishing disclosure
Initial DisclosureFBI and Arctic Wolf reporting identify Kali365 as a phishing-as-a-service platform that targets Microsoft 365 and Microsoft Entra accounts through OAuth device-code phishing and an adversary-in-the-middle mode called "Cookie Link." The service is distributed through Telegram channels, offers AI-generated phishing lures, automated campaign templates, real-time victim-tracking dashboards, and token capture, and has been observed in campaigns against organizations worldwide that led to mailbox access, malicious inbox rules, and occasional new device registrations.
Show sources
- FBI warns of Kali365 phishing service targeting Microsoft 365 accounts — www.bleepingcomputer.com — 25.05.2026 15:45
- FBI warns of Kali365 phishing service targeting Microsoft 365 accounts — www.bleepingcomputer.com — 25.05.2026 15:45
- FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens — www.infosecurity-magazine.com — 25.05.2026 12:30