Earlier

Spot compromised cards and credentials before transaction-based detection.

Prioritized

Use exposure-focused triage to handle highest-risk records first.

Actionable

Enable immediate card re-issue, account controls, and fraud response workflows.

Kali365 phishing kit bypasses MFA on Microsoft 365

A look at the cost of compromise

Attack + Goal

April 2026 on Microsoft 365 enterprise users. Goal was broad corporate account takeovers and extortion.

Result

Widespread corporate account compromises, multi-factor authentication bypasses, and unauthorized access to cloud communications and files.

Method

Device code phishing via the Kali365 kit, hijacking OAuth tokens to bypass passwords and multi-factor checks.

Financial Impact

Unquantified direct theft losses, forensic investigations, and account remediation expenses.

In April 2026, cybercriminals launched Kali365, a phishing platform distributed via Telegram that targets corporate Microsoft 365 environments. The blast radius spans organizations worldwide, allowing low-skilled threat actors to gain full access to victim Outlook emails, Teams messaging, and OneDrive file storage. The attack relies entirely on credential and token theft using a device code authorization trick. Attackers send lures posing as document-sharing alerts, prompting employees to enter codes into legitimate login portals. Once completed, the platform steals valid OAuth access tokens. This grants the attackers persistent session access while completely bypassing multi-factor authentication without requiring passwords. The resulting intrusions expose organizations to corporate espionage, data theft, and internal business email compromise.

PreBreach ID Guard flags stolen OAuth tokens, and auto-remediates by cutting off persistent Microsoft 365 access even when MFA has already been bypassed.

Sources BleepingComputer · FBI IC3

TagsFraudATO

Fraud Intelligence Workflows

Built to reduce time between detection and containment.

Payment Card Monitoring

Detect compromised payment card records with PCI-aligned display controls and auditable access logs.

Banking Credential Detection

Track stolen account credentials and support rapid account lockout and re-authentication actions.

Fraudulent Check Signals

Review stolen check-image indicators and trigger preventive account controls before cash-out attempts.

Crypto Attribution Support

Correlate wallet indicators with threat actors to improve fraud investigation and reporting context.

Our Data

We Detect 8 Asset Types

Credentials

Email/password pairs, usernames, malware source. Passwords masked by default, audit-logged reveal.

Cookies

Browser cookies, session cookies, authentication tokens from compromised systems.

Access Tokens

Authentication tokens, session tokens, OAuth tokens from compromised systems.

Credit Cards

Payment card numbers (PAN), card brand, expiry. Last 4 digits only, CVV never exposed.

User PII

SSNs, phone numbers, addresses, full names. Masked by default (***-**-1234), audit logged.

Bank Accounts

Account credentials, financial account totals. Account numbers masked, financial exposure calculated.

Malware

Infected system data, screenshots, IOCs, stealer logs. Forensic evidence with secure viewing.

Fraudulent Checks

Stolen check images with OCR extraction. Visual review with PII warnings.

Our Differentiator

DarkArmor Features & Fraud Benefits

Feature

Benefit

Real-Time Token Monitoring

Invalidate compromised cookies in real-time, making session hijacking impossible for the fraudster.

Infostealer Intelligence

Identify which of your users have malware on their devices before they try to log into your platform.

Pre-Dark Web Alerts

Get a "heads up" on fresh data hauls before they are sold, giving you days—not hours—to force password resets.

Reduce False Positives

By knowing exactly which accounts are compromised, you can stop "blanket blocking" and reduce friction for legitimate users.

We don't just monitor the dark web; we monitor the crime as it's happening

Fraudsters are using professional-grade infostealer malware to snatch live session tokens and cookies, now building at scale thanks to the power of AI. Our technology provides a direct window into this criminal infrastructure. We see the data within minutes or hours after it’s exfiltrated from a victim's device.

How it Works

Fresh data from active campaigns

1

Set up Integration

There is no installation, and we don't touch your network. Use our platform or API.

2

Monitor active campaigns

Our feed picks up +50k data points a day from current and ongoing malware and phishing campaigns.

3

Alert and remediate

Get alerted based on your customized needs so you can act early, weeks or months before a breach occurs.

Strengthen Your Fraud Program

Operationalize prebreach intelligence across fraud, risk, and security teams.