New Kali365 Phishing Kit Threatens Banks, Bypasses Multi-Factor Authentication
Kali365 is a phishing-as-a-service kit that targets Microsoft 365 accounts, allowing attackers to steal session tokens and bypass multi-factor authentication. The financial services industry is a prime target because it controls funds and sensitive data. Compromised accounts can lead to wire fraud and business email compromise.
The Federal Bureau of Investigation recently warned that Kali365 is being sold through Telegram, putting attacks within reach of hackers with limited technical skills. The latest public information does not disclose the exact date of the warning, the kit's price or the amount lost by victims. It does confirm that Kali365 primarily targets Microsoft 365, underscoring the need for banks and financial institutions to strengthen monitoring of session tokens and anomalous logins.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.