ctipilot.ch

Kali365 PhaaS

campaign · campaign:fbi-psa260521-kali365-phaas-oauth-device-code-m365-mfa-bypass

Telegram-distributed phishing-as-a-service exploiting the OAuth device-code flow for persistent Microsoft 365 token capture bypassing MFA (FBI PSA260521).

Coverage timeline
0
first 2026-05-23 → last –
no data
Peak priority
no matching entries
Sources cited
0
0 hosts
Sections touched
0
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

No published entries reference this entity yet.

explore in graph

Entries about Kali365 PhaaS

No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.