Kali365 Phishing Kit Hijacks Microsoft 365 OAuth Tokens | MSSP Advisory

HighCredible Report
DateMay 25, 2026
📋Executive Summary
The FBI has issued a warning about Kali365, a phishing-as-a-service platform that steals Microsoft 365 OAuth tokens through adversary-in-the-middle attacks. The platform allows low-skill attackers to bypass multi-factor authentication by intercepting and replaying legitimate OAuth tokens during the authentication process. Kali365 operates as a turnkey service that makes advanced phishing attacks accessible to criminals without technical expertise.
⚠️Why It Matters for MSSPs
Your RMM and PSA platforms likely authenticate through Microsoft 365, making your entire client management stack vulnerable if tokens get hijacked through this attack method. Every client using Microsoft 365 with OAuth-based authentication faces immediate risk of account takeover even with MFA enabled, and you need to warn them before they get compromised through your recommended security stack.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Phishing

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.