MICROSOFT 365
Kali365 Beats Microsoft 365 MFA With a Real Login
Kali365 still hijacks Microsoft 365 through the real device-code login, and the FBI’s four fixes are Entra Conditional Access policies most users cannot set.
The FBI’s May 21 Kali365 alert tells Microsoft 365 tenants to block device code flow in Entra. The trap uses a genuine Microsoft verification page, so the browser padlock and the MFA prompt both look correct.
Kali365 is a Telegram-sold kit that grabs OAuth tokens after the victim types a short code. Arctic Wolf, which got inside the panel in April 2026, put the rent at $250 for 30 days, or $2,000 for 365 days, across three tiers paid in cryptocurrency.
Kali365 Turns Microsoft’s Own Login Into the Lure
The Bureau’s May 21 public service announcement (alert I-052126-PSA) says the kit was first seen in April 2026. It is built so a less-skilled operator can run a full Microsoft 365 takeover without ever seeing a password.
Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.
Federal Bureau of Investigation, IC3 PSA I-052126-PSA
The FBI Cyber Division posted the same warning the day the PSA went out.
https://x.com/FBICyberDiv/status/2057567340401705090
The lure is usually an email dressed as a file-share, a signing request, or another familiar cloud notice. It carries a device code and tells the reader to open Microsoft’s real verification page and paste it in. That page is legitimate. The victim signs in, completes MFA, and authorizes a device that is not theirs.
Arctic Wolf described the April wave in those terms, saying the campaign relied on high-fidelity lures directing victims to Microsoft’s legitimate device login flow, where users unknowingly authorized threat actor-initiated sessions. Once the code is accepted, the operator captures access and refresh tokens. Outlook, Teams, and OneDrive then open without another password or another MFA challenge. Inbox rules can hide the mail that would have warned the user.
Inbox training does not catch this, because there is no fake domain to spot. The useful instruction is narrower: never type a Microsoft device code unless you started the sign-in on the device in front of you.
The FBI’s Four Steps Are Entra Admin Work
The PSA is written as tips to protect yourself. Every item is a Conditional Access change in the Entra admin center. A person who only has Outlook cannot do any of it. The work belongs to a Conditional Access Administrator, which is why the practical Microsoft 365 admin checklist for Kali365 is a tenant job, not an inbox setting.
THE FBI STEPS, MAPPED TO ENTRA
| FBI recommendation | Matching Entra control | Who can set it |
|---|---|---|
| Block device code flow for all users, with limited exceptions for required business processes | Conditional Access authentication-flows condition, grant set to block | Conditional Access Administrator |
| Audit existing device code flow usage before creating the policy | Sign-in logs filtered to Authentication protocol = Device code flow | Same admin role, before the block goes live |
| Block authentication transfer so users cannot pass a PC sign-in to a phone | Authentication-flows condition for authentication transfer, grant set to block | Same admin role |
| If a full block is not possible, exclude emergency access accounts to prevent lockouts | Break-glass accounts left out of the policy | Same admin role, required to keep a recovery path |
Microsoft’s own how-to page tells organizations to get as close as possible to a unilateral block on device code flow, then allow it only for documented leftover tools. The policy should start in report-only so the sign-in logs can show who still depends on the path. Authentication transfer is a separate toggle on the same screen, aimed at people who bounce a PC login onto a personal phone.
None of that lives in Outlook, Teams, or OneDrive. Home Microsoft 365 users, and small tenants with no one in the Entra portal, can report a phish to IC3 and can refuse unexpected codes. They cannot publish the policy the FBI listed first.
Storm-2372 Ran This Play Before Kali365
Device code phishing was not new in April 2026. Microsoft Threat Intelligence documented a Storm-2372 device code phishing campaign that had been active since August 2024, using lures that looked like WhatsApp, Signal, and Microsoft Teams. On February 14, 2025, Microsoft said the actor had shifted to the Microsoft Authentication Broker client ID, which can yield a refresh token, an actor-controlled device in Entra ID, and a Primary Refresh Token.
On July 31, 2026, Microsoft updated that same write-up and assessed Storm-2372 as an initial-access sub-cluster of Midnight Blizzard. Huntress later said Kali365 activity showed the same Authentication Broker client-ID move, which is how a short code becomes a durable foothold rather than a one-off mailbox peek.
Proofpoint told defenders it had watched device-code phishing jump starting in February 2026. By April the Telegram product had a price list. The FBI named it on May 21, 2026.
THE DEVICE CODE TIMELINE
- August 2024: Microsoft later dates the start of Storm-2372’s device-code phishing against governments, NGOs, and industry.
- February 13, 2025: Microsoft publishes the Storm-2372 campaign write-up and tells tenants to block the flow where they can.
- February 14, 2025: Storm-2372 shifts to the Microsoft Authentication Broker client ID so a refresh token can register a rogue device.
- February 2026: Proofpoint tracks a sharp rise in device-code phishing.
- April 2026: The FBI later dates Kali365’s first appearance, sold on Telegram.
- May 18, 2026: Huntress starts seeing device-code sign-ins from Tencent Cloud in AS132203.
- May 20, 2026: That spike peaks at over 80 successful UserLoggedIn events in Huntress telemetry.
- May 21, 2026: IC3 publishes PSA I-052126-PSA.
- June 11, 2026: Huntress publishes its panel teardown.
- September 8, 2026: Barricade Cyber Solutions says the kit has added a full adversary-in-the-middle path and a Zer0day-branded portal.
The gap between Microsoft’s 2025 write-up and the 2026 PSA is the part the consumer alerts skip. The login path stayed available. The criminal side productized it.
What Blocking Device Code Flow Breaks
Microsoft now says the quiet part in its managed-policy docs. Device code exists for gear that cannot host a normal browser login, and attackers use it more than customers do.
Device code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.
Microsoft, Entra Conditional Access managed policies
A tenant-wide block still collides with Microsoft’s own hardware and admin tools. The Learn page for Teams devices tells admins to keep an exception for room resource accounts and to leave the Device Registration Service out of a blunt block. The same page tells anyone still using Azure CLI or other command-line admin tools on headless boxes to find those accounts in the logs first.
WHAT A TENANT-WIDE BLOCK CAN BREAK
- Teams Rooms: Meeting-room consoles that still enroll through device code need a scoped exception, not a hole left open for every user.
- Input-poor hardware: Smart TVs, printers, and IoT boxes were the original reason the flow exists.
- Headless admin tools: Azure CLI and similar command-line logins on servers without a browser still show up in some tenants.
- Leftover kiosks: Digital signage and shared stations that were never moved to a better login fail first when the policy flips to On.
That is why the FBI’s second step is an audit, and why the fourth step protects break-glass accounts. Flip the block with no exceptions and you can lock a lobby screen, a room console, or, in a bad edit, the admin recovery path. Leave it off and Kali365 keeps a Microsoft-signed front door.
Microsoft now ships a Microsoft-managed policy that blocks device code. It lands in Report-only, cannot be renamed or deleted, and lists Entra ID P2 or Microsoft 365 Business Premium as a prerequisite. Microsoft says it may turn those managed policies on no less than 30 days after they appear, unless an admin opts out. Eligible tenants get a slow push. Other tenants still have to build the policy themselves, then argue with whoever owns the conference rooms.
Huntress Clocked a Takeover in 42 Seconds
Huntress researcher Tanner Filip did not stop at the FBI’s four-step lure. Starting May 18, 2026, the Huntress SOC watched device-code sign-ins pour in from Tencent Cloud. On May 20 the count hit over 80 successful UserLoggedIn events. Validin pivoting, then a wider sweep, produced more than 240 IPs hosting panel variants.
In one case users were sent to a Canva page that claimed the email was encrypted. Clicking View opened a real Microsoft login, then a prompt for the code. After the code landed, the browser went to a page that said Document Expired. Huntress timed persistent access at as little as 42 seconds. Changing the password later does not kill the stolen refresh token.
KALI365 IN THE LOGS
- Speed: Huntress timed a full takeover in as little as 42 seconds from the Microsoft prompt to attacker access.
- May 20 spike: Over 80 successful UserLoggedIn events from Tencent Cloud in AS132203.
- Lure library: Each panel edition ships 33 built-in templates, from OneDrive and DocuSign to Copilot, Intune, and the admin center.
- Shop floor: Huntress counted 100+ API endpoints, role-based operator access, a domain marketplace, and crypto billing through OxaPay.
The FBI described document-sharing impersonation. The template list is wider. Copilot notices, Intune enrollment, voicemail, and admin-center lures are in the same kit, some marked as pro features. Names on the panels also drift. Huntress found Kali365, Octopi365, and a shorter-lived Freedom365 brand on related infrastructure, and treated them as the same platform.
The operator console is the part a PSA cannot show. Edition E1 keeps a token vault, an Outlook webmail proxy, Telegram capture alerts, Cloudflare Workers, Turnstile bot checks, and an optional residential geo-proxy so Microsoft’s sign-in log looks local. Edition E2 adds AI-assisted business-email-compromise drafts, a high-value mail queue for wires and payroll, a credentials scanner, and Exchange admin abuse that can add mail connectors and toggle DKIM. Edition E3 is the reseller desk, with self-serve account recovery against a crypto payment and no human review.
Companion apps finish the job. OctoLink Live opens a real Chromium window, already signed in, to admin.microsoft.com, entra.microsoft.com, or outlook.office.com, which is harder to spot than scripted Graph traffic. That is the product Microsoft 365 tenants are up against: not a clumsy fake login, a storefront that turns a six-digit code into a staffed fraud desk.
The Telegram Kit Did Not Stop in May
A Microsoft spokesperson said at the time of the PSA that the company was actively working to disrupt the cybercriminal ecosystems behind phishing-as-a-service and account takeover activity. The managed policy pack is the concrete control that followed on the Entra side. It still arrives in report-only. It still needs the listed licenses. It still needs a Teams Rooms exception in any tenant that uses those consoles.
On September 8, 2026, Barricade Cyber Solutions said operators had added a full adversary-in-the-middle path that steals passwords and live session cookies, plus a second login portal branded Zer0day. Device-code theft was the original pitch. Cookie theft is the extra door for tenants that finally blocked the flow, or for victims who never see a device code at all.
The four FBI steps still close the original hole, if someone with Entra rights turns them on and then watches the sign-in logs for the room consoles and CLI accounts that break. Kali365 is still for sale. The Microsoft page in the lure is still real. The policy that would make that page useless is still an admin choice Microsoft will only auto-flip, slowly, for tenants that already pay for Conditional Access.
-
NEWS4 months agoWarzone Leaves Xbox One and PS4 After Season 06
-
NEWS4 months agoMicrosoft AI Was Set Free to Build Its Own Frontier
-
MICROSOFT 3654 months agoMicrosoft IQ Turns Workplace Data Into a Metered Agent Brain
-
NEWS4 months agoXbox Games Showcase 2026 Split the Catalog in Two
-
MICROSOFT 3654 months agoNadella Banned Addiction Talk While Scout Kept Heartbeat
-
NEWS4 months agoModern Warfare 4 Splits Its Audience Before the October Launch
-
NEWS4 months agoInfinity Ward Bets Modern Warfare 4 on a Paid DMZ
-
NEWS4 months agoDragonwilds Hits Xbox, but Steam Saves Stay Put
