I Found an MFA-Bypassing Phishing Kit on the Dark Web

I Found an MFA-Bypassing Phishing Kit on the Dark Web

Source: YouTube · John Hammond · published Aug 12, 2026 · 18:03

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: The FBI has issued a warning regarding "Cali 365," a phishing-as-a-service platform that uses device code phishing to bypass multi-factor authentication and steal Microsoft 365 access tokens 0:05. This threat is evolving with variants like "Octo Pie 365," leveraging AI and streamlined desktop tools to facilitate widespread business email compromise and wire fraud 2:02.

Key Takeaways:

  • Bypassing MFA via Device Code Phishing: Cali 365 utilizes a technique called "device code phishing," where victims are tricked into authenticating via a legitimate Microsoft authentication broker. This allows attackers to capture OAuth tokens without needing the victim's password or MFA codes, effectively bypassing security controls 2:15.
  • Sophisticated Phishing Panels: The platform offers a backend panel where operators can generate numerous phishing lures (e.g., fake Adobe Acrobat or DocuSign pages), track campaign metrics, and view a "token vault" of stolen accounts. This interface allows attackers to read victim inboxes and send emails impersonating the user 3:37.
  • AI-Enhanced Post-Exploitation: Attackers are using AI, specifically Claude, to analyze stolen email threads and generate drafted replies. This automation makes it significantly easier to launch business email compromise (BEC) and wire fraud scams by hijacking ongoing conversations 6:05.
  • Distribution and Tooling: The phishing kits are distributed via Telegram and dark web forums like exploit.in. The ecosystem includes dedicated Electron-based desktop applications (e.g., OctoLink) that allow operators to manage sessions, send mass emails, and interact with stolen mailboxes with minimal technical friction 7:18.
  • Rapid Evolution and Persistence: Despite FBI warnings and the shutdown of original Cali 365 operations, variants like Octo Pie 365 and Freedom 365 have emerged. The threat actors continue to operate, utilizing "vibe-coded" tools that are rapidly developed and deployed, indicating a resilient and adaptive criminal ecosystem 1:44.

Closing Statement: The emergence of AI-assisted, token-based phishing platforms like Cali 365 represents a significant escalation in cyber threats, as they lower the barrier to entry for attackers and bypass traditional identity security measures. Organizations must prioritize identity-centric threat intelligence and monitor for anomalous OAuth token usage to mitigate these risks.

Sources:

  • 0:05 FBI public service announcement warning about the Cali 365 phishing platform.
  • 2:15 Explanation of device code phishing and how it bypasses MFA.
  • 3:37 Overview of the phishing panel's functionality, including lure generation and token vaults.
  • 6:05 Discussion on the use of AI to analyze emails and draft fraudulent replies.
  • 7:18 Details on Telegram distribution and desktop application tooling.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

The FBI put out this notice. The Federal Bureau of Investigation is issuing this public service announcement to warn the public about an emerging phishing-as-a-service platform called Cali 365. This PSA is back in May. Cali 365 first appeared in April of 2026. It has been primarily distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication without intercepting the user's credentials. Now, in case you're not familiar with a phishing-as-a-service platform, I've got one pulled up for you right here. This is a back-end panel where a hacker or a cyber criminal would be able to log in and then actually manage, generate, create, and send multiple phishing emails and then keep track of their organized campaigns as to what vic…