Kali365 Exploits Microsoft Device Login to Access Corporate Data
Kali365, a Phishing-as-a-Service (PaaS) platform, has been targeting US companies using device code phishing that abuses Microsoft's legitimate authentication process.
The attack begins with a phishing page impersonating a trusted service such as SharePoint, OneDrive, or DocuSign. Kali365 includes 34 lure templates that operators can switch between for different phishing scenarios.
Once the victim successfully authenticates, attackers obtain the OAuth access and refresh tokens issued to the application or client that initiated the device-code flow.
The US is the main geographic target of Kali365, with more than 80 public sessions linked to the phishing kit appearing in ANY.RUN's database each week. Security teams can explore this activity using ANY.RUN Threat Intelligence Lookup.