Kali365 Phishing Kit Exploits Microsoft Authentication for Corporate Data Access
A malicious phishing kit called Kali365 is targeting US organizations by using Microsoft's legitimate authentication page as a gateway to corporate data. The attackers use a device code phishing technique, where victims are presented with a webpage impersonating trusted business services such as SharePoint or OneDrive. Once the victim authenticates on Microsoft's real authentication page, the attackers obtain access and refresh tokens that provide continued access to email, documents, and cloud resources.
The attack can lead to financial fraud, sensitive data exposure, operational disruption, and higher response costs for US companies. To reduce Kali365 risk, security leaders need current campaign intelligence, faster validation of suspicious activity, and better preparation for how the threat may evolve.
ANY.RUN's Threat Intelligence Feeds deliver newly observed indicators through STIX/TAXII, API, and SDK to support alert enrichment, retrospective searches, and blocking decisions. The platform also provides an Interactive Sandbox that reveals the full attack chain faster, from the phishing page and redirect paths to network activity and the transition into Microsoft's authentication flow.
Organizations using ANY.RUN have reported 94% faster threat triage, up to 21 minutes less MTTR per case, and up to 20% lower Tier 1 workload. These gains lower response costs, improve the use of existing SOC resources, and shorten the window for token abuse to escalate into fraud, data exposure, or operational disruption.