Kali365 phishing kit bypasses MFA and steals Microsoft logins
2026-05-27T20:51:52Z•914b362ee6e6e6dde0eb2fd10f21adab722d0c0d442c374cc7be9c35d7ed74f5
Adobe TargetClickFix campaignCloudflare spoofingDeno RATFox TempestGhost CMSKali365LinkedIn phishingMFA-bypassMicrosoft 365OneDriveOutlookTeamscode-signing-fraudcredential-theftfake-installersphishingphishing-kitsupply-chainthreat-intel
What happened
The FBI warns of a new phishing kit called “Kali365” that phishers are using to bypass MFA and steal Microsoft credentials, enabling long-term access to Outlook, Teams, OneDrive and other Microsoft 365 resources. The same Malwarebytes feed highlights related threats: Adobe Target abuse in LinkedIn-themed phishing, fake installers on GitHub/SourceForge distributing a Deno RAT, a large ClickFix campaign exploiting Ghost CMS to push malware via fake Cloudflare verification pages, and a fraudulent malware-signing service (Fox Tempest) used to bypass security checks. Overall this set of reports rat
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 914b362ee6e6e6dde0eb2fd10f21adab722d0c0d442c374cc7be9c35d7ed74f5
- Enrichment time
- 2026-05-27T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.