Kali365, a phishing kit designed to abuse Microsoft’s legitimate device authentication process, is emerging as a significant threat to organizations in the United States by using trusted login workflows to gain unauthorized access to corporate Microsoft 365 environments. Instead of relying on fake login pages, the phishing kit directs victims to Microsoft’s genuine device login portal and persuades them to enter attacker controlled device codes. Once authentication is completed, attackers can obtain access and refresh tokens that may allow continued access to corporate email accounts, cloud resources, and business documents. Security researchers note that this approach creates risks including data exposure, financial fraud, operational disruption, and increased incident response costs while making malicious activity more difficult to identify because users are authenticating through a legitimate Microsoft service.
According to telemetry from ANY.RUN, more than 80 public sandbox sessions associated with the Kali365 campaign are observed each week, with organizations in the United States identified as the primary targets. Researchers explained that the phishing campaign generally unfolds in three stages. Victims are first presented with phishing pages impersonating trusted business services such as SharePoint, OneDrive, or DocuSign. The fraudulent pages then redirect users to Microsoft’s legitimate device authentication portal, where they are instructed to enter attacker supplied device codes. Once authentication is completed, attackers can receive OAuth access and refresh tokens that provide continued access to Microsoft 365 email, documents, and cloud resources without requiring users to submit passwords directly to the phishing site. Because authentication takes place on Microsoft’s official platform, the activity may initially appear legitimate, potentially allowing attackers additional time to misuse compromised accounts before security teams detect suspicious behavior. Researchers warned that a single approved device code request can develop into a broader compromise affecting multiple business systems.
Security experts stated that organizations should not rely solely on traditional email filtering to defend against this type of phishing activity because Kali365 operators can rapidly change domains, hosting infrastructure, and phishing URLs. Instead, they recommend combining actionable threat intelligence with security monitoring platforms such as SIEM, SOAR, Threat Intelligence Platforms, and firewall technologies to improve detection and response capabilities. ANY.RUN said its Threat Intelligence Feeds distribute newly identified indicators of compromise through STIX, TAXII, API, and SDK integrations, allowing security teams to enrich alerts, perform retrospective investigations, and implement blocking decisions using the latest campaign intelligence. The company also highlighted the role of its Interactive Sandbox in enabling analysts to observe phishing pages, redirect chains, browser activity, scripts, and attacker infrastructure while automatically generating reports containing verdicts, indicators of compromise, tactics, techniques, procedures, and behavioral evidence. These capabilities are intended to help Tier 1 analysts identify malicious activity more quickly and provide higher quality information when escalating complex incidents to senior security teams.
Researchers also recommended using Threat Intelligence Lookup to examine Kali365 infrastructure, lure pages, and campaign activity beyond individual alerts. For activity targeting organizations in the United States, analysts can search using the query threatName:”kali365″ AND submissionCountry:”US” to identify related infrastructure and targeting patterns. According to ANY.RUN, the campaign has affected organizations across manufacturing, technology, healthcare, government, consulting, and managed security service provider sectors. The company added that its Threat Intelligence Reports provide manually compiled research covering active malware campaigns, phishing operations, advanced persistent threat groups, and cybercriminal activity to support threat hunting and incident investigations. Organizations using ANY.RUN reported measurable operational improvements, including 94 percent faster threat triage, up to 21 minutes lower mean time to respond per incident, up to 20 percent lower Tier 1 analyst workload, and 30 percent fewer escalations from Tier 1 to Tier 2 teams. These improvements help security operations centers reduce response times, improve resource utilization, and shorten the opportunity for attackers to exploit stolen authentication tokens before broader business systems, cloud services, and sensitive enterprise data are affected.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.