Security News

Cybersecurity news aggregator

MEDIUM Attacks Dark Reading

FBI-Flagged Phishing Kit Kali365 Expands Its Reach

  • What: FBI-Flagged phishing kit Kali365 expands its reach
  • Impact: Cybercriminals using Kali365 are targeting users with phishing attacks
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Cyber Risk Securing AI Agents Before They Go Rogue Is Next to Impossible Securing AI Agents Before They Go Rogue Is Next to Impossible by Rob Wright Jun 2, 2026 5 Min Read Cyber Risk Anthropic to Open Mythos AI to EU's ENISA Anthropic to Open Mythos AI to EU's ENISA by Jai Vijayan Jun 1, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Cyberattacks & Data Breaches Threat Intelligence News FBI-Flagged Phishing Kit Kali365 Expands Its Reach Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. Jai Vijayan , Contributing Writer June 2, 2026 4 Min Read Source: babar ali 1233 via Shutterstock The operators of Kali365, a phishing-as-a-service platform that drew considerable attention for helping attackers bypass multifactor authentication (MFA) on Microsoft 365 accounts, have significantly broadened both their capabilities and their target list. In a report released this week, Arctic Wolf described Kali365 as evolving from a purely Microsoft-focused phishing kit to a broader account-compromise platform that targets digital identities across AWS, Okta, Xerox DocuShare, and several Russian online services. The most notable among them is MAX Messenger, a Russian state-backed messaging platform with more than 80 million users that the Russian government has promoted as the country's national message service. A Dangerous Expansion in Targeting Kali365's expansion into MAX Messenger and other Russian online services suggests "a deliberate, consistent focus on Russian consumer-Internet platforms, alongside the operator's existing Western enterprise targets," Arctic Wolf said. "A phishing operator who can convert MAX account takeovers into propagation has access to one of the largest installed messaging bases in the Russian-speaking world." Related: Securing AI Agents Before They Go Rogue Is Next to Impossible Kali365 has emerged as one of the more prominent examples of a device code phishing kit in recent months. Device code phishing abuses the authentication workflow used by smart TVs, printers, and other devices when they lack a full browser or keyboard and require users to log in via a separate device. For example, it's the code that a streaming device like a Roku or Apple TV might display on a smart TV screen and which the user would then enter on their phone or computer to complete the login and link the two devices. In a device code phishing attack, a threat actor generates a legitimate OAuth 2.0 device authorization request and then tricks a victim into entering the associated code on a legitimate login page, through a phishing email impersonating a shared OneDrive file or a security verification prompt, for example. Once the victim authenticates and completes any required MFA steps, the service — in Kali365's case initially Microsoft365 — issues access tokens to the attacker's session, granting the attacker access to the victim's account without ever requiring their credentials. In these attacks , MFA does not prevent compromise, because the victim is unknowingly completing the authentication process on behalf of the attacker. The insidious nature of the attack prompted the FBI to issue a public service announcement last month warning users about Kali365 and describing how the attack works. "Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities." Related: Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense A Growing Threat Across Sectors and Regions Arctic Wolf's analysis of the operation showed Kali365 has become an even bigger threat in recent weeks. Researchers at the company were able to identify the platform's live command-and-control (C2) infrastructure and from there identify a cluster of 126 malicious hosts that were active between early and late May, all serving the same kit. The hosts, according to Arctic Wolf, impersonate a wide range of platforms, including Microsoft Outlook, Microsoft Live, Okta SSO, Xerox DocuShare, the German email provider GMX, Amazon Web Services naming conventions, and several major Russian online services, such as Mail.ru, Yandex Disk, and the social network Odnoklassniki. The sheer breadth of the impersonated platforms showed that Kali365 has evolved from being a specialized platform for stealing M365 tokens to a much broader credential theft platform that presents a threat to enterprise organizations across regions. Related: Anthropic to Open Mythos AI to EU's ENISA "Arctic Wolf strongly recommends implementing comprehensive security awareness training to equip users with the skills needed to quickly identify and report suspicious activity, including the tactics observed in this campaign," the security vendor said. The company's report also included specific measures that organizations can take to spot potentially malicious activity connected with Kali365. Kali365 is one among multiple device code phishing kits that have become available to threat actors in recent months. Other examples include Tycoon2FA , Venom, and CYB3R. In a recent report, Push Security reported observing a "huge spike" in device code phishing activity recently with at least 14 such kits currently available in the wild. Some of these are existing phishing-as-a-service platforms adding device code functionality and some are new. "Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users," the security vendor warned. "In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. See more from Jai Vijayan Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 How Enterprises Are Harnessing Emerging Technologies in Cybersecurity Access More Research Webinars The Frontier AI Era: Why Cybersecurity Must Move at Machine Speed Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack Defending in the Shadow Era: When the CVE Feed Goes Dark Building SecOps That Make the Most of Every Dollar AI-Powered Credential Security: Intelligence Without Exposure More Webinars Editor's Choice Cybersecurity Operations 20 Leaders Who Built the CISO Era: 2 Decades of Change 20 Leaders Who Built the CISO Era: 2 Decades of Change by Dark Reading Editorial Team May 12, 2026 41 Min Read Application Security It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight by Jai Vijayan May 12, 2026 5 Min Read Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. Subscribe Webinars The Frontier AI Era: Why Cybersecurity Must Move at Machine Speed Tuesday, June 23, 2026 1:00 PM EDT Build vs. Buy: The Hidden Cost of Building Your Own AI Se

Share this article