I Found an MFA-Bypassing Phishing Kit on the Dark Web
The FBI warns of a new phishing-as-a-service platform, Cali 365, which exploits Microsoft 365 access tokens to bypass multi-factor authentication, with cybercriminals using Telegram to distribute phishing campaigns and obtain user credentials via device code phishing.
MAIN POINTS FROM TRANSCRIPT
- Cali 365 is a phishing-as-a-service platform targeting Microsoft 365 access tokens.
- The platform is distributed via Telegram, allowing bypass of multi-factor authentication.
- Device code phishing is used to capture OAuth tokens without user credentials.
- Over 150 IP addresses host variants of the phishing kit panel.
TAKEAWAYS
- The FBI has issued a public service announcement about the emerging threat of Cali 365.
- Cybercriminals use backend panels to manage and track phishing campaigns.
- Device code phishing leverages legitimate login methods to intercept tokens.
- The cybersecurity community, including IBM X-Force and Huntress, actively tracks these threats.