Kali365 phishing kit bypasses MFA and steals Microsoft logins

2026-05-27T20:51:52Z914b362ee6e6e6dde0eb2fd10f21adab722d0c0d442c374cc7be9c35d7ed74f5
Adobe TargetClickFix campaignCloudflare spoofingDeno RATFox TempestGhost CMSKali365LinkedIn phishingMFA-bypassMicrosoft 365OneDriveOutlookTeamscode-signing-fraudcredential-theftfake-installersphishingphishing-kitsupply-chainthreat-intel

What happened

The FBI warns of a new phishing kit called “Kali365” that phishers are using to bypass MFA and steal Microsoft credentials, enabling long-term access to Outlook, Teams, OneDrive and other Microsoft 365 resources. The same Malwarebytes feed highlights related threats: Adobe Target abuse in LinkedIn-themed phishing, fake installers on GitHub/SourceForge distributing a Deno RAT, a large ClickFix campaign exploiting Ghost CMS to push malware via fake Cloudflare verification pages, and a fraudulent malware-signing service (Fox Tempest) used to bypass security checks. Overall this set of reports rat

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
914b362ee6e6e6dde0eb2fd10f21adab722d0c0d442c374cc7be9c35d7ed74f5
Enrichment time
2026-05-27T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.