OAuth Device Code Phishing: How EvilTokens and Kali365 Bypass MFA and What Microsoft 365 Teams Must Do Now
OAuth device code phishing exploits a legitimate Microsoft authentication flow to steal persistent tokens, bypassing MFA entirely. With a 37x surge in 2026 and the FBI warning about Kali365, here is the definitive M365 defense guide.

Recommended tool: Pluralsight
Level up your security skills with expert-led courses. Free 10-day trial, then access thousands of courses across cloud security, networking, and certifications.
Get weekly security insights
Cloud security, zero trust, and identity guides — straight to your inbox.
Continue Learning
SOC Analyst Level 1 Roadmap
Get job-ready for your first Security Operations Center role.
Microsoft Cloud Solution Architect
Cloud Solution Architect with deep expertise in Microsoft Azure and a strong background in systems and IT infrastructure. Passionate about cloud technologies, security best practices, and helping organizations modernize their infrastructure.
Share this article
Questions & Answers
Related Articles
Need Help with Your Security?
Our team of security experts can help you implement the strategies discussed in this article.
Contact Us