phishing
Kali365 Phishing Kit Broadens Beyond Microsoft 365 to AWS, Okta, and Russian Platforms
Kali365, the phishing-as-a-service kit the FBI flagged in May for stealing Microsoft 365 tokens past MFA, has broadened its targets to AWS, Okta, Xerox DocuShare and Russian services, Arctic Wolf reports — extending its core OAuth device-code phishing to far more of the stack.