The Kali365 platform, distributed via Telegram since April, lets attackers steal OAuth tokens and access Outlook, Teams, and OneDrive without a password

If you see one of these emails — check carefully, you may be under attack.

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal…