phishing
FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
High
Summary
The FBI has issued a warning about Kali365, a Telegram-based phishing-as-a-service platform, following its use in April attacks targeting Microsoft 365 accounts. This service lowers the barrier to entry for cybercriminals, allowing them to capture OAuth tokens and bypass multi-factor authentication, granting them access to user accounts without needing passwords. The platform’s ease of use and features, including AI-generated lures and token storage, have facilitated widespread attacks, highlighting the evolving sophistication of cybercriminal operations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
