Kali365: Phishing-as-a-Service Bypasses Microsoft 365 MFA

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Preparation & Acquisition

Attackers rent the phishing-as-a-service platform Kali365 to target Microsoft 365 accounts without their own technical expertise.

T1583 – Acquire Infrastructure T1588.002 – Obtain Capabilities: Tool
  • PhaaS platform Kali365, publicly reported on August 5, 2026 by The Hacker News
  • Ready-to-use attack package sold as a paid subscription service
  • Specifically targeted against Microsoft 365
  • Over 80 US companies attacked per week, also active in Europe
PHASE 2/5 · Initial Access via Phishing

The attacker generates a controlled device code and lures the victim into entering it on the genuine Microsoft page.

T1566 – Phishing T1621 – Multi-Factor Authentication Request Generation
  • Abuse of the legitimate Microsoft device code flow
  • Attacker-controlled device codes are pushed onto the victim
  • Entry occurs on the genuine Microsoft login page – appears legitimate
  • No classic software vulnerability, hence no CVE number
PHASE 3/5 · MFA Bypass

Because the victim actively approves the login on genuine Microsoft infrastructure, multi-factor authentication is handled as part of the process.

T1621 – Multi-Factor Authentication Request Generation T1550 – Use Alternate Authentication Material
  • MFA does not protect because the victim confirms the process themselves
  • The second factor is handled within the confirmed device code flow
  • The attacker's device is authorized through the confirmation
PHASE 4/5 · Persistence

The attacker gains persistent access to the account that survives even a password change.

T1098 – Account Manipulation T1136 – Create Account
  • Persistent, lasting access to the Microsoft 365 account
  • Access remains despite a password change (authorization ≠ password)
  • Granted authorization must be explicitly revoked
PHASE 5/5 · Collection & Access

The attacker accesses emails, documents, and connected cloud resources.

T1114 – Email Collection T1530 – Data from Cloud Storage T1114.003 – Email Forwarding Rule
  • Access to the entire Microsoft 365 business correspondence
  • Access to files in OneDrive and SharePoint
  • Access to other connected cloud services and data
  • Possible signs: unexplained email forwarding and new rules
Short & clear answers
Frequently asked questions about this incident
Am I affected by Kali365?
In principle, this threat affects all Microsoft 365 users. If you use Microsoft 365 for email, documents, or team collaboration, you are a potential target. According to the report, the attack is primarily active in the US (over 80 companies per week), but it is explicitly active in Europe too, making it relevant for German businesses.
Why doesn't my two-factor authentication protect me?
The attack abuses Microsoft's legitimate device-code flow, in which the victim signs in themselves on the genuine Microsoft page and actively approves the access. Because the sign-in happens on Microsoft's real infrastructure and the second factor is handled as part of that victim-approved process, multi-factor authentication does not intervene protectively. MFA nevertheless remains important against many other types of attacks.
How do I know if my account has been compromised?
Be suspicious of unexpected prompts to enter a short code on a Microsoft sign-in page when you didn't start the sign-in yourself. Also check your account settings for unknown devices or logins from unusual regions. Unexplained email forwarding rules, newly created rules, or messages marked as read that you didn't open can also indicate unauthorized access.
What should I do right now?
Raise awareness among your team immediately: never enter a sign-in code on a Microsoft page if you didn't start the sign-in yourself. Check with your IT lead whether the device-code flow is even needed and restrict it if not. Monitor for unusual logins and keep an incident response plan ready.
Is it enough to just change my password?
No. The attack creates persistent, ongoing access that often remains even if you change your password, because the granted authorization is not the same as the password. If you suspect a compromise, existing authorizations and active sessions must be specifically revoked. When in doubt, involve your IT provider or a security expert.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.