Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.
Originally published at darkreading.com

The FBI-flagged Kali365 phishing-as-a-service platform has expanded beyond its original Microsoft 365 targets to now include AWS, Okta, and Russian platforms. The threat actor toolkit leverages device code phishing techniques to compromise enterprise authentication systems across multiple cloud service providers.
Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.
Originally published at darkreading.com
60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.