Kali365 and EvilTokens: The New Phishing-as-a-Service Threat

Professional phishing kits lower barriers for attackers, bypassing MFA with ease.

ThreatVectr Newsdesk· 2 min read
Kali365 and EvilTokens: The New Phishing-as-a-Service Threat
Share

Phishing-as-a-service platforms like Kali365 are reshaping the cyber threat landscape by enabling attackers to bypass multifactor authentication (MFA) protections. Notably, these platforms make it easier for less experienced hackers to launch sophisticated attacks. The Federal Bureau of Investigation (FBI) recently warned that platforms like Kali365, which includes AI-generated phishing lures and OAuth token capture, are increasingly being used by threat actors.

Microsoft 365 (M365) is a primary target. Threat actors leverage platforms such as Kali365 and EvilTokens to steal OAuth tokens, circumventing MFA protections. Sekoia researchers noted EvilTokens has been circulating since February, while Arctic Wolf detected a massive device code phishing campaign linked to Kali365 in April. Four days later, Gurucul echoed these concerns, emphasizing the professional nature of these attacks.

These services are not just the work of isolated hackers but are full-scale commercial operations. With subscriptions starting at $250 for 30 days, Kali365 allows attackers to create branded phishing lures impersonating services like Adobe Acrobat Sign and SharePoint. Arctic Wolf observed that threat actors create malicious inbox rules to suppress security alerts, prolonging access to compromised accounts.

A significant shift is required in cybersecurity strategies. "Multifactor authentication is no longer a sufficient defense," said Robert Beggs, CEO of Digital Defence. "Organizations must implement a defense-in-depth approach, including conditional access policies and proactive OAuth token revocation." Despite multiple requests, Microsoft did not address how often these proactive measures were being adopted.

The FBI advises restricting device code flow in M365 environments and adopting conditional access policies. Failure to do so could result in widespread unauthorized access, as these attacks exploit the OAuth device code authentication flow.

Fritz Jean-Louis, of Info-Tech Research Group, advocates for identity-centric security, stressing the need to treat phishing as an identity compromise risk. While the emphasis remains on MFA, Jean-Louis highlights the importance of monitoring for anomalous behavior and strengthening session controls.

But the core question remains: Are organizations truly prepared to enforce these protections, or will the allure of convenience continue to leave them vulnerable?

© 2026 Threat Vectr