I Found an MFA-Bypassing Phishing Kit on the Dark Web

I Found an MFA-Bypassing Phishing Kit on the Dark Web

🎙 John Hammond 👥 2.2M 📅 August 12, 2026 ⏱ 18 min 👁 36K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

Kali365device code phishingOAuth token theftphishing-as-a-serviceMicrosoft 365

Summary

In this video, John Hammond investigates Kali365, a phishing-as-a-service platform that targets Microsoft 365 accounts and bypasses multi-factor authentication (MFA) through device code phishing. He begins by referencing an FBI public service announcement warning about the platform, which emerged in April 2026 and is distributed via Telegram. Hammond explains the device code phishing technique, where victims are tricked into entering a code on a legitimate Microsoft login page, allowing attackers to steal OAuth tokens without needing credentials or MFA. He then shows a back-end panel of the phishing kit, demonstrating how operators can manage campaigns, view captured tokens, and even read victims’ emails. The video also covers the distribution of Kali365 on dark web forums and Telegram, and includes an analysis of desktop applications used by the operators. Hammond extracts and examines the code of these applications, revealing that they are Electron-based and contain hardcoded domains and client IDs. He highlights the role of AI in generating phishing lures and automating email replies for business email compromise. The video concludes with detection recommendations and emphasizes that despite the FBI notice, the threat persists with new variants like OctoPi365.

188 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real phishing kit, including its technical workings, distribution channels, and the tools used by attackers. The argumentation is solid, supported by references to FBI PSA, Huntress research, and Flare threat intelligence. The presenter demonstrates hands-on analysis of the kit’s code, which adds credibility. However, some claims rely on third-party reports and the video includes a sponsor segment, which may introduce bias.

77 words

Title / Content Match

The title accurately reflects the content: the video presents a phishing kit found on the dark web that bypasses MFA.

Quality & Reliability

8/10

The video is based on FBI PSA, Huntress research, and Flare threat intelligence, with technical analysis of the phishing kit's code and infrastructure. The presenter demonstrates hands-on investigation, but some claims rely on third-party reports and the video includes a sponsor segment.

Key Moments

Cited Sources

  • FBI PSA on Kali365 — Official FBI public service announcement warning about Kali365 phishing service.
  • Huntress Blog: Kali365 Device Code Phishing Kit — Detailed technical analysis of Kali365 and OctoPi365 by Huntress.
  • BleepingComputer: FBI warns of Kali365 phishing service — News article covering the FBI warning and details of the phishing service.

Concurring Sources

  • FBI PSA on Kali365 — FBI warning aligns with the video's claims about the threat.
  • Huntress Blog: Kali365 Device Code Phishing Kit — Huntress research corroborates the technical details presented.
  • BleepingComputer: FBI warns of Kali365 phishing service — News article supports the existence and impact of the phishing kit.

External References

Contribution & Novelties

The video provides an in-depth look at a specific phishing-as-a-service kit, including its technical implementation and distribution. It offers practical insights for defenders, such as the importance of session revocation and device-code controls. The analysis of the desktop applications’ code is particularly novel, revealing hardcoded domains and client IDs.

Pour aller plus loin :

  • Device Code Phishing — Background on the OAuth device code flow used in this attack.
  • Phishing as a Service — General overview of phishing and its evolution into a service model.
  • OAuth Token Theft — Official OAuth 2.0 specification, relevant to understanding token theft.

98 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-researched video that is accessible to a broad audience.

Reliability 8/10