Kali365 Phishing Kit Exploits Microsoft Authentication to Target US Organizations
A sophisticated phishing kit called Kali365 has been targeting US organizations by turning legitimate Microsoft login into a gateway to corporate data.
The phishing kit, built to abuse legitimate Microsoft authentication, uses device code phishing and OAuth access to obtain access and refresh tokens that provide continued access to Microsoft 365 email, documents, and cloud resources.
Kali365 targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud, operational disruption, and costly incident response.
The attack unfolds in three main stages: the lure, Microsoft authentication, and OAuth access. The phishing kit uses SharePoint-themed lures to draw victims into the authentication flow, and once they complete authentication, attackers may obtain access and refresh tokens that provide continued access to corporate data.