Kali365 Targets US Companies with Device Code Phishing
Kali365, a Phishing-as-a-Service (PaaS) platform, has been targeting US companies using device code phishing that abuses Microsoft's legitimate authentication process. The attack begins with a phishing page impersonating a trusted service, such as SharePoint or OneDrive, and once the victim interacts with it, they are directed to Microsoft's legitimate device login page where they enter an attacker-provided code.
Once the victim successfully authenticates, attackers obtain OAuth access and refresh tokens issued to the application or client that initiated the device-code flow. These tokens may provide continued access to Microsoft 365 email, documents, and cloud resources without directly stealing the victim's password.
The US is the main target of Kali365 activity, with over 80 public sessions linked to the phishing kit appearing in ANY.RUN database each week, indicating sustained activity against US companies. The attack has been ongoing for a few months, and security teams can explore this activity in ANY.RUN Threat Intelligence Lookup using specific query parameters.
To defend against Kali365 and similar phishing campaigns, security teams should connect continuous detection, fast triage, and proactive threat hunting. This includes keeping detection systems updated with fresh phishing intelligence, giving Tier 1 the context to confirm faster, and building a more proactive defense by regularly reviewing analyst-compiled research.