Submind YouTube summaries
Thumbnail for I Found an MFA-Bypassing Phishing Attack on Microsoft 365

I Found an MFA-Bypassing Phishing Attack on Microsoft 365

Watch on YouTube

Video summary

The Federal Bureau of Investigation has issued a public service announcement warning about an emerging phishing-as-a-service platform known as Cali 365, which first appeared in April and gained significant traction by May. This malicious infrastructure allows cyber threat actors to obtain Microsoft 365 access tokens while bypassing multi-factor authentication without ever needing the victim's actual credentials. The FBI notice highlights how these platforms are primarily distributed via Telegram, enabling hackers to manage campaigns from a centralized back-end panel where they can generate phishing emails, track victims who fall for traps, and steal valuable security keys. Alongside Cali 365, another variant named Octo Pie 365 has emerged around the same timeline, creating a complex ecosystem of duplicate panels that offer extensive functionality including self-service crypto payments and desktop applications designed to streamline cybercrime operations. The core mechanism behind these attacks relies on a technique called device code phishing, which exploits legitimate Microsoft authentication flows often used for TV sign-ins or remote access scenarios where typing passwords is inconvenient. In this scheme, victims are lured via social engineering tactics—such as fake PDF updates from Adobe Acrobat—to websites that prompt them to copy and paste a generated code into the official Microsoft login page. While the victim's email address, password, and multi-factor authentication codes are sent directly to legitimate Microsoft servers for verification, the hacker intercepts the resulting OAuth tokens in real-time. These stolen tokens act like digital cookies, granting attackers full access to read emails, send messages, and compromise accounts without requiring any further interaction from the user or knowledge of their specific login details. To maximize damage after gaining initial access, these platforms have evolved into sophisticated cybercrime ecosystems that leverage artificial intelligence to automate post-exploitation activities. The back-end panels allow operators to view captured tokens in a "vault," launch desktop applications built on Electron technology to directly browse victim inboxes, and utilize AI tools like Claude's Sonnet to analyze email threads and draft convincing replies for business email compromise or wire fraud scams. Researchers have analyzed the source code of these unauthorized desktop apps, revealing that they are essentially unsecured web interfaces bundled into executable files using standard installers like NSIS. These applications hardcode old domains while migrating URLs to new variants, demonstrating a clear intent to maintain persistent access and conduct further financial theft once an attacker has established a foothold within the victim's Entra ID environment. Despite the FBI warning and industry discussions regarding these threats, activity from Cali 365 and its successors continues unabated on underground forums like exploit.in and Telegram channels where threat actors advertise their services. While some chatter suggests operators are closing shop following regulatory pressure, new campaigns persist with little slowdown, indicating that the demand for such tools remains high among desperate cybercriminals. Security firms emphasize that identity-first platforms capable of detecting credential leaks across dark web markets can help lock down compromised accounts before incidents occur at odd hours, but the sheer volume and automation provided by AI make these attacks increasingly difficult to stop manually. The consensus is clear: as long as there are victims willing to click on deceptive links or scan QR codes for device verification, platforms like Cali 365 will continue to pose a severe risk to organizations relying on Microsoft 365 infrastructure.
Read the full video transcript
The FBI put out this notice. The Federal Bureau of Investigation is issuing this public service announcement to warn the public about an emerging phishing-as-a-service platform called Cali 365. This PSA is back in May. Cali 365 first appeared in April of 2026. It has been primarily distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication without intercepting the user's credentials. Now, in case you're not familiar with a phishing-as-a-service platform, I've got one pulled up for you right here. This is a back-end panel where a hacker or a cyber criminal would be able to log in and then actually manage, generate, create, and send multiple phishing emails and then keep track of their organized campaigns as to what victims they sent them out to, what victims have fallen for the trap and they've stolen their access keys for, and then the hackers have an easy interface to be able to look through your emails and do more damage. This is an active panel online and I don't quite have credentials. No, thanks, 1Password. But, in this video we'll take a closer look what the inside of these panels look like, some of the tooling and the code that they use, and some of the chitchat on Telegram. With the FBI notice published and the industry seeing a ton of these Cali 365 campaigns, there are a lot of people chatting about this. Here's some info from IBM X-Force and their threat intel exchange. It's been in the news. Some of our channel partners have been covering this, Put Security, Flare, and even hey, us at Huntress, right? My day job. We've been tracking this too. Big shout out to Tanner, he always sees awesome stuff. And the Huntress blog carries an interesting new name in the mix, Octo Pie 365, alongside Cali 365. Oh, hey, speaking of the FBI, cool little episode the other day, hey, when we got to hang out with the FBI cyber division assistant director, Bret Leather. That was a pretty cool opportunity. I'll leave a link below. I hope you go tune in. Anyway, I wanted to introduce the Octo Pi name in your brain as well, because that is alongside the Cali 365 conversation. And we had seen this activity start to blow up just about the same timeline as the FBI notice. And throughout all the communication, you'll see this discussion of OAuth tokens and how they're captured with this technique called device code phishing. I've talked about device code phishing in a ton of other videos, but a quick crash course, you can think of it like you're trying to log in to Netflix on your television. You don't have a full keyboard while you're holding your remote, so you can't really type in your password. So, the screen just gives you a string of letters or numbers in a code that lets you authenticate. On the screen here, you can see a little social engineering lie, a scam, a lure, maybe some email or some place on the internet drove them to this website that looks like an Adobe Acrobat sign in to get some important update PDF document. But, when they tell you to copy this code and sign in to Microsoft, what they do is they open up a real, actual, legitimate login authentication method that Microsoft allows to just use that device code that they provided and then finish the sign in. So, the victim's legitimate sign in, the email address they enter, their password, even their multi-factor authentication, goes to legitimate Microsoft, but because of this device code fish, the hacker is able to sit in the middle and see and retrieve those OAuth tokens. Kind of like the cookie that lets them log in without needing any of the info on their real credentials or MFA. Now, do you remember that back-end panel that I showed you just a moment ago? Remember, this portal is where the hacker could sign in and generate or create as many of those lures as they wanted to. Some more of the research here from Tanner, he says, "Using Valdin, we were able to find over 150 IP addresses hosting several variants of that phishing kit panel." One of the attacks led victims to a a hosted on Canva, and then that would lead them to uh the lure of a again device code that was redacted here, but another important PDF or shared document. And then the sign-in with Microsoft authentication broker. One of the coolest things with Tanner's research in this Hunter write-up is how it's tracking Cali 365 is totally a vibe coded fishing as a service platform. And now we're seeing a good many of sort of these duplicate identical panels with a different name Octo Pie. But we were able to dig into them and see, "Look, there are a ton of different lure formats, a ton of different functionality, and self-service crypto payments, desktop applications for operators, a whole cybercrime ecosystem." So look at all these different lures. I showed you the Adobe Write PDF review light mode warning. Sorry, flashbang. You remember this? This was just one out of like 33 of these that they have. It's kind of crazy to see all that it could just crap out and generate here. And with these findings, you might have seen in the text it's all just React pages that we could pull down, we could recreate that inside of the back-end panel. What do the operators get to see? Following screenshots created here contain fake data, but they are rendered using the actual bundles. Here's the inside look at one of those Octo panels. Octo Pie, Octo Link, Octo whatever they're calling it now. So putting our hacker hat on, right? Bad hacker, cybercriminal threat actor, we'll play pretend adversary. This is our lures page, right? We could see all the created and generated phishing links, custom landing pages for SharePoint, OneDrive, Microsoft Teams, DocuSign. You can see the domain that they're tied to, the number of visits, the number of captures that have come from it. Kind of crazy. Another one is the token vault for the actual victims they would have gotten. We can import tokens manually, but they are the captured Microsoft 365 accounts. They let you read inboxes, send emails, and more. So the inbox button here is pretty sinister because that will literally, genuinely take the threat actor into like a generated clean simple user interface to just scroll through their email inboxes, go through all their email. So it's easy breezy beautiful CoverGirl to, I don't know, come up with business email compromise or wire fraud scams. In fact, they've even powered that with some AI. So there's literally a section apparently for Claude's son it to analyze these email threads and generate in reply drafts. So they could hijack a thread and say, "Hey, wire the money here." That's kind of crafty. You know, you got to give the devil his due. Uh hackers are using AI. All right. So now that we've gotten a look inside the panel, the couple other things that I wanted to do in this video was to take a look at how this is being distributed on Telegram and take a look at the desktop applications. There's some really good insight in the write-up itself. So of course, I'll leave that linked in the video description, but I do have the desktop applications here on my desktop. I want to check these out after we take a look at the Telegram side of the house. At the start of the video, I mentioned that our channel partner Flare also dug into Kali 365 and Octo Pi 365 and all the fishing kit things. And we actually collaborate with Flare quite frequently, like us and Huntress and all, right? Uh Evil Tokens when that campaign was out and about and Kali 365 we were discussing with them just as well. And they have a really cool perspective because look, they're seeing this kind of being shared around. Flare has the threat intel from the dark web, like the cybercrime underground. You can see a listing here on exploit.in, notoriously known like Russian speaking cybercrime hacking forum. Someone in a buying and selling malware threat, they say, "Hey, contact me if you need Kali 365." Look, in case you're not familiar, Flare is an identity first cyber threat intelligence platform that collapses the gap between an alert and actual remediation. With their integration between Entra ID and other identity providers, the moment that there is any of your team members, employees, accounts, and users actually has any of their information exposed, like their credentials are in an info-stealer malware leak site, or information's for sale on Telegram or the dark web forums, or even the clearnet or ransomware leak sites, then you could have that account locked down, actually session quarantined, and remediated and resolved before an incident occurs at like 2:00 a.m. on a Saturday. If you've seen any of my videos before, you know that I am a huge Flare fanboy, and they have always supported the channel, and they are the sponsor of today's video. So, please do give them some love, link below in the video description. But, you know me, I like a little bit of a tactical topic, so we'll use Flare to actually continue some of the research and go find more about Cali 365. Let me collapse here, and a lot of these are probably just going to be some news syndication. Oh, someone posted on Dread. One of the coolest things about Flare is they give us a raw link to go see it at the source. Oh my goodness, this is a post from a week ago. Did anyone try Cali 365 yet? I've been getting better at fishing the last couple months. I've been doing some business email compromise attacks, too, with my own fishing page to companies of my country. I'm sorry, Rome 00, but I don't think this is it. Worker Bee responds, I'm genuinely surprised any type of fishing still works in 2026. It's really true, people are dumb. All right, [clears throat] I feel like it's a little bit of victim blaming, Worker Bee. Oh, this is the exploit.in one they showcased. This was the screenshot they had on their blog. Can I go visit that? Oh, well, I can't really read that language, but well, it's what you'd expect, you know. A lot of folks distributing it, though, you can see Cali 365 available. Some folks saying, "Hey, I got it set up." Someone says, "I need that Cali 365. Who has Cali 365?" BJ 17681, anyone with an update on Cali 365 who knows about that Wow, guys are a little desperate. All right, I'm going back a bit, and I found a Cali 365 user sending Telegram messages inside of a Telegram channel called Cali 365. So, I'm curious about that one and I'm loading the page here. Cali 365 with a description of World Cup 2026. So, I click view in Telegram. Uh and I think they either scrub the channel or I don't know. Let's join it. Yeah, no, there's there's nothing in there. So, let's just take a little peek at our OctoLink Sender and OctoLink Live. I want to try to look at Sender first. I'm double-clicking on that. Look at it. The description here, OctoLink B2B email sender desktop app. If I take a look at the properties, it is not signed, but it does have filled in details here for everything pertinent to it. And oh, okay, it looks like it's starting up in the background here. Oh, I do not have a login. Nor do I actually want to log in cuz I don't do that. How about OctoLink Live 3? They're probably both going to ask me for authentication. Yeah, I don't have that. Oh, but you can see the electron logo on the icon at the very top here. These are electron applications, it seems. So, with that, I'm going to hop over to a REMnux virtual machine. I do have the files staged here and I'm going to open that up with my terminal. Put them inside of a directory for us to work with here. You can see that both of these do state that they are using the Nullsoft installer. I think that's NSIS. So, if we're to consider both of these files as kind of their own archives and treat them actually using this 7-Zip utility, we could use like the list sub command or just L on any of these. Let's get OctoLink Live and you'll be able to see some of the pertinent DLLs here. Of course, NSIS for the installer and app-64, all part of this plugins directory that is usual boilerplate for that NSIS tech. So, we could go ahead and extract with the X command there on that OctoLink. Now, you'll be able to see that created that plugins directory and I'm going to have to escape out that dollar sign so my command line doesn't think that it is a variable. And let's then go ahead and extract the app64. That will break out everything, including the resources and everything that might have been bundled with that application here. And you'll see things pertinent to running this like inside of Chromium because okay, Electron is having a little bit more of that web native capability. But what we're interested in is the resources folder here for Electron apps. That app.asar is something that we'd love to be able to look at. We can install the Electron ASAR utility. And does that have a list command? Yeah, okay. I think we can give it that app.asar, and that will dump all of the things that are pertinent in here. So if we were still for whatever reason squeamish or uncertain about the connection between OctoPrint, OctoPrint, and Cali 365, I guess the original 1.0 executable is whatever part of the resources folder there. And it includes all of the node modules that are included in the original source code here. So it's neat to be able to list all these out, but ultimately we want to extract them and see the pertinent source code. Gosh, the node modules folder is just absolutely uh bloated. Let's extract app.asar. Oh, and it needs a destination. Let's just put it like uh output directory, and now it will live in that output directory for us. Can I open that up with Sublime Text? Do I have that in my uh arguments? I do. It's in my path at least. Okay, so we have the icon. Looks a lot better here than it did on Windows in the desktop. package.json pretty clear. Tells us the main script or JavaScript code that this runs out of is that index.js. And it looks like there are some I think probably boilerplate Electron things that happen at the very start here. But then we are retrieving some of the modules and then building out the capability for having that front end. Uh the menu options that we would have seen in the very top bar. We could scroll through index.js, but there's not going to be a whole lot of here other than okay, it's presenting the interface to us. IPC looks like a lot of the communication back and forth with how you interact with the panel. You can see the entries to like log in, log in with two factor, get me refresh token, et cetera. The panel API is probably where a lot of the more interesting things tend to happen. And that way again, we can probably see some of the potential endpoints that the panel might be exposing or revalidate findings that we could have seen from Valdin or Shodan. Other things that would be part of the research process, right? Preload.js, prt off.js. Ooh, primary refresh token authentication in pure node. That's neat and looks pretty AI, right? >> [laughter] >> HTTP helpers though, and then all of the like genuine implementation to be able to do well, okay, device registration, granted all of the authentication capabilities. So it's like device code fish in JavaScript. That is kind of cool, if I may say. Look, we know this is all vibe coded. So like you can have whatever opinion that you would like there, but it's crazy to see the extent of streamlined tooling. You know what I mean? Service window.js. Oh, is this to like give them the quick conveniences of like exploring their inbox for one thing? Presumably, here's a launch Outlook capability. So yeah, it would just open it up in their browser capability so that it's extremely easy for the operator. You barely have any extra clicks or understanding. You're just immediately in their inbox. That must be the interface that we were able to see in a lot of the things that this allows it to do. Just in an easy side-by-side a desktop application. Do we need to even look at the sender, honestly? I think you're probably going to see the similar understanding of node electron application. Package.json for the email sender once again pretty outright. This carries a dist electron with it. Whoa. Main.js and others look like there is intended to be a lot more convenience for hey yeah, being able to just mass spam out emails and they've got the database schema put together here though. That's kind of interesting to be able to look at. Oh yeah, you can see their old domains that they just have hard coded in here. Wow. Migrate stored panel URLs from old domains now to OctoPi. >> [laughter] >> Sorry, I just think it's interesting to see some of like the potential breadcrumbs. Like obviously they're using the default client ID. I presume that's for the Microsoft authentication broker one that they send the device code fish from and you could see like the database paths they would have on their system. Like piecing this all together here, all this intelligence is just kind of interesting. There are some more details on the desktop applications again in the Hunters write up that I'll have linked down below if you're interested. Again, really just wild to see okay, utilizing a browser like this means it's kind of going to be coming from a normal legitimate web browser using the SSO cookies as if that's the real end user. That's the real end goal here, right? Is to take advantage of that full end user, that person, that identity, any end user and then even operate with emails that will be sent after the fact for business email compromise, for wire fraud, for further post exploitation and damage that can be done once they have a foothold inside your Entra ID environment. Some detection rules here for you and again uh FBI's been chatting about this because it was just such a big big campaign. But that's not to say the campaign is really over, right? Uh we saw the Telegram chat messages when the threat actors had noticed after the FBI PSA was released, hey we're shutting our doors, we're closing up shop, we're ceasing operations. But we're still seeing activity and it's not easy to say, okay, you know what, Cali365, OctoPi365, Freedom365, whatever the fishing kit du jour is, it's not particularly slowing down. We can see that AI is really enabling all of that, and they're going after you and your teammates, and your employees, and your colleagues, and your peers, and you and your identity. So, really love Flare and the great work that they've been doing. Again, super duper thankful for them sponsoring this video and always offering their support. And it's always super cool to be able to collaborate on cases like these. So, please do give them some love. Link below in the video description. Huge shout out to Flare. Thanks so much for your support. Thank you for watching this video. I hope you had a little bit of fun and hey, cracking open the code, taking a look at what these panels look like, what the desktop applications look like, and seeing a little bit more behind the scenes. Thanks so much. I'll see you in the next video.