Source: FBI warns of Kali Oauth stealers | CSO Online
Author: unknown
URL: https://www.csoonline.com/article/4176464/fbi-warns-of-kali-oauth-stealers.html
ONE SENTENCE SUMMARY:
FBI warns Kali365 phishing steals Microsoft 365 OAuth tokens, bypasses MFA via device authorization, urging conditional access blocks and transfer restrictions.
MAIN POINTS:
- FBI alerted organizations about a new Kali365-enabled phishing wave targeting Microsoft 365 accounts.
- Kali365 captures OAuth access tokens rather than stealing usernames or passwords.
- Bypassing multi-factor authentication occurs because valid tokens authenticate without credential interception.
- Attackers impersonate trusted cloud document-sharing services in convincing phishing emails.
- Victims are instructed to enter a specific code on a legitimate Microsoft website.
- Entered code authorizes the attacker’s device to access the victim’s Microsoft account.
- Mitigation includes conditional access policies blocking device code flow for most users.
- Exceptions should be narrowly granted only for essential business processes needing code flow.
- Blocking authentication transfer policies prevents rights handoff from corporate PCs to mobile devices.
- World Economic Forum data shows phishing is CEOs’ top concern and growing across organizations.
TAKEAWAYS:
- Token-based phishing can defeat MFA without ever capturing user credentials.
- Legitimate login pages don’t guarantee safety when attackers abuse device authorization workflows.
- Conditional access controls are central to reducing exposure to device code phishing.
- Preventing authentication transfers limits attackers’ ability to persist across devices.
- Rising phishing volume makes rapid policy hardening and user awareness critical.