Kali365 and Why Stealing Passwords Is No Longer Enough
Barracuda Networks, Wednesday, September 2nd, 2026
Barracuda details Kali365 phishing that abuses legitimate Microsoft 365 authentication flows to seize sessions and tokens, not just passwords.
Barracuda analyzes Kali365, a phishing toolkit and technique set that abuses legitimate Microsoft 365 authentication workflows rather than simply harvesting credentials.
The attacks use device code phishing and adversary-in-the-middle methods to obtain sessions and tokens, which grants access to cloud email and files even where a password alone would not.
Because the flows involved are legitimate Microsoft ones, the activity can look normal to defenders watching only for credential theft. The post explains why password-centric defenses fall short and what token and session-level protections matter.