Last Update: 08/01/2026 at 2:00 PM EST

Phishing Kits Hijack Microsoft 365 Tokens

Coverage from BleepingComputer, The Record, and others

Articles

9

Active Days

141

The Topic

Phishing Kits Hijack Microsoft 365 Tokens topic image

Cybercriminals are increasingly using device-code phishing, malicious OAuth applications, and adversary-in-the-middle techniques to obtain valid Microsoft 365 authentication tokens without directly stealing passwords or MFA codes. Platforms including Tycoon2FA, ARToken, Forg365, and Kali365 package these methods into phishing-as-a-service offerings that support campaign delivery, token management, mailbox monitoring, and access to Microsoft cloud data. The activity matters because completed legitimate authentication can give attackers persistent access to Outlook, Teams, OneDrive, SharePoint, and connected single sign-on services.

First Article: 02/19/26

Latest Article: 07/09/26

History

07/23/20260 new articles

The story broadens from device-code phishing tied mainly to token theft into a wider Microsoft identity-abuse ecosystem that now explicitly includes OAuth redirect abuse and adversary-in-the-middle phishing. It also places more emphasis on commercialized phishing services and their post-compromise capabilities against Microsoft cloud data and connected SSO apps.

07/23/20260 new articles

The story now frames the activity less as a general wave of MFA-bypassing attacks and more as a packaged OAuth-abuse ecosystem built around phishing-as-a-service operators and affiliates. It also adds a clearer operational shift toward token-management, persistence, and post-compromise automation, including a reported disruption and recovery cycle for Tycoon2FA.

  • Tycoon2FA resumed operations after a March disruption.
  • Attackers now abuse OAuth authorization flows, not just device-code phishing.
  • ARToken includes mailbox monitoring and inbox-rule changes.
  • Forg365 combines AI-assisted lures with cookie persistence.
  • The FBI warned about Kali365 and token-focused phishing services.
07/21/20264 new articles

The story has broadened from device-code token theft into a more mature, multi-tool Microsoft 365 account-takeover ecosystem. The latest reporting adds a wider set of phishing-as-a-service platforms, real-time cookie capture, and concrete post-compromise persistence tactics.

  • New PhaaS brands include Kali365, Tycoon2FA, Forg365, and ARToken.
  • Attackers now capture session cookies and refresh credentials in real time.
  • Campaigns use AI-generated lures, QR codes, and fake CAPTCHA pages.
  • Post-compromise actions include inbox rule creation and mailbox monitoring.
  • Telegram-distributed phishing infrastructure is part of the threat ecosystem.
05/14/2026Topic Formed

Attackers are increasingly abusing OAuth device-code and related sign-in flows to steal authentication tokens, bypass MFA, and take over Microsoft and SaaS accounts through phishing kits, vishing, and adversary-in-the-middle techniques.