← Back to news

FBI warns of Kali Oauth stealers

CSO Online22/05/2026, 17:51
Read full article →

Summary

AI-Generated

Key Points:

  • New phishing attacks utilizing the Kali365 tool are enabling cyber criminals to steal Microsoft 365 access tokens and bypass multi-factor authentication (MFA) without credential interception.
  • The attack impacts Microsoft 365 accounts, allowing unauthorized access through captured Oauth tokens, posing significant risks to organizational security.
  • Recommended actions include implementing conditional access policies to block code flow for all users and restricting authentication transfer policies to prevent unauthorized access from mobile devices.

Technical Details: Kali365 captures Oauth tokens linked to victims' Microsoft 365 accounts by tricking users into authorizing attackers' devices through phishing emails that appear legitimate.

MITRE ATT&CK Techniques:

  • T1566.001 - Phishing: Spearphishing Link (Initial Access)
  • T1078 - Valid Accounts (Defense Evasion)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.