A Phishing Kit Is Stealing Microsoft 365 Sessions, Not Passwords
A Microsoft 365 account gets flagged. You reset the password, check that multi-factor authentication is on, and close the ticket. That is the correct answer to a stolen password.
You will miss this one, because the password was never stolen.
On May 21st the FBI published a public service announcement about a phishing service called Kali365, sold on Telegram and aimed at Microsoft 365. Researchers at SpyCloud counted around 500 paying subscribers. The victims in their data are construction firms, manufacturers, accountants, medical practices and school districts.
The sign-in is what makes it work. Your user gets something that looks like a shared document. It sends them to a genuine Microsoft sign-in page and asks them to type in a short code. The page is real, the sign-in is real, and they approve it on their phone exactly as trained. The code came from a bad actor, so what they approved was a stranger’s computer. Microsoft issues that computer the sign-in tokens, and those tokens survive a password change, because they prove a sign-in happened, not who signed in. The feature is called device code sign-in, it exists for screens with no keyboard, and it is on by default.
Two behaviours after that decide how long it lasts. It deletes the warning mail as it arrives, so the sign-in alert and the new-device notice are gone before anyone even sees them. And it registers a device of its own in your directory, which survives everything except being removed by name.
Then it waits, watching the mailbox for the words invoice, payment and wire. If it lands on a global administrator, the whole tenant goes with it.
Switch off the sign-in method it needs. Microsoft’s own guidance is to block device code sign-in as close to everywhere as you can manage. Whoever runs your Microsoft 365 can do it with 1 policy. Ask them to run it in report-only mode first, which records what it would have blocked without blocking anything, so nothing legitimate breaks when it goes live.
Change the order of the response. First, revoke the account’s sign-in sessions, which is what makes those tokens useless. Then reset the user’s password and set up the second factor again. After that, remove any registered device you cannot account for, because that is the step people skip and that device is what gives the bad actor a way back into your systems. Then read the mailbox rules, since the kit creates them to hide itself.
Ask one question about the logs. A session that started this way stays tagged that way in the Microsoft sign-in logs, in a field called Original transfer method. Whoever runs your tenant can search it and find sessions that started weeks ago.
The fix that actually holds is a passkey stored in the phone or laptop itself, or a physical security key. A texted code or a tap-to-approve prompt does not stop this, because the bad actor takes the session after the approval has already happened.
Password resets don’t fix stolen session tokens. Revoke the sessions and delete the devices.
NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.
Sources: FBI Internet Crime Complaint Center public service announcement, 21 May 2026. SpyCloud Labs research, 11 June 2026. Microsoft Entra conditional access documentation on blocking authentication flows.
