Advisory Summary

Ferrilli is monitoring public reporting and FBI guidance regarding Kali365, a Phishing-as-a-Service platform that targets Microsoft 365 users through device code authentication and OAuth token theft. The attack can direct a user to a legitimate Microsoft verification page, where the user unknowingly authorizes an attacker-controlled session. If successful, the attacker may obtain access and refresh tokens that allow access to Outlook, Teams, OneDrive, SharePoint, and other connected Microsoft 365 resources without requiring the user password.

Higher Education Impact

For higher education institutions, this threat presents a meaningful risk because Microsoft 365 is commonly used for email, collaboration, file storage, student services, and administrative operations. A successful attack could lead to unauthorized mailbox access, data exposure, malicious forwarding rules, fraudulent internal communications, or access to sensitive student, employee, financial, and institutional information. Because the activity may appear as legitimate authentication traffic, institutions may not immediately identify the compromise without reviewing sign-in logs, OAuth consent activity, and related Microsoft Entra indicators.

How Ferrilli Can Assist

Ferrilli can assist schools by helping review Microsoft Entra sign-in activity, identifying device code authentication usage, assessing Conditional Access configurations, and evaluating OAuth application consent exposure. Ferrilli can also support the implementation of controls to reduce risk, including blocking or limiting device code flow where appropriate, reviewing high-risk app permissions, validating emergency access exclusions, strengthening MFA and Conditional Access policies, and helping schools document exceptions where legitimate business use exists.

Summary

Ferrilli recommends that institutions treat Kali365 as a Microsoft 365 identity and access security concern and continue monitoring trusted cybersecurity guidance. Schools that would like assistance reviewing their Microsoft 365 environment, validating potential exposure, or implementing protective controls should contact Ferrilli at gethelp@ferrilli.com.

References:
• FBI IC3 Public Service Announcement: https://www.ic3.gov/PSA/2026/PSA260521
• CISA Phishing Guidance: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one