
FBI Warns About Cali 365 Phishing-as-a-Service Platform Exploiting Microsoft 365 Authentication
The FBI issued a public service announcement in May warning about Cali 365, a phishing-as-a-service (PhaaS) platform first detected in April 2026, distributed primarily via Telegram. The platform enables cybercriminals to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) without stealing user credentials by exploiting device code phishing, a technique mimicking legitimate Microsoft authentication flows. Operators use backend panels to generate phishing lures (e.g., fake Adobe Acrobat or SharePoint login pages), track victims, and access compromised email inboxes via captured OAuth tokens. Research by Huntress and IBM X-Force identified over 150 IP addresses hosting variants of the kit, including a rebranded version called Octopi 365, which offers self-service crypto payments, AI-powered email analysis (via Claude Sonnet), and desktop applications built with Electron for mass email spamming. The platform’s infrastructure includes hardcoded domains, default Microsoft client IDs, and React-based interfaces, with threat actors actively discussing its use on forums like exploit.in and Telegram channels. Despite the FBI’s PSA, activity persists, with attackers leveraging AI to automate business email compromise (BEC) and wire fraud. The video demonstrates reverse-engineering the desktop apps, revealing their reliance on Node.js and Chromium-based frameworks to impersonate legitimate users.