Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is a device code phishing kit that abuses legitimate Microsoft authentication to steal access and refresh tokens from US organizations The attack follows a three-stage chain: SharePoint/OneDrive-themed lure → redirect to Microsoft's real device login portal → OAuth token theft ANY.RUN telemetry shows 80+ public sessions weekly, with the US as the primary target across manufacturing, healthcare, government, and MSSPs Because authentication occurs on Microsoft's legitimate page, the activi
Analysis
TL;DR
- Kali365 is a device code phishing kit that abuses legitimate Microsoft authentication to steal access and refresh tokens from US organizations
- The attack follows a three-stage chain: SharePoint/OneDrive-themed lure → redirect to Microsoft's real device login portal → OAuth token theft
- ANY.RUN telemetry shows 80+ public sessions weekly, with the US as the primary target across manufacturing, healthcare, government, and MSSPs
- Because authentication occurs on Microsoft's legitimate page, the activity appears routine, delaying detection and enabling prolonged unauthorized access
- Defense requires expanding beyond email filtering with live threat intelligence feeds, Tier 1 sandbox analysis, and proactive threat hunting using TI Lookup queries
Why It Matters
Kali365 represents an evolving class of OAuth-based phishing that bypasses traditional email security by leveraging Microsoft's own authentication infrastructure, making detection significantly harder for SOC teams. For US organizations, a single compromised account can cascade into financial fraud, data exfiltration, and operational disruption with delayed visibility. This campaign underscores the critical need for behavioral detection and threat intelligence integration rather than reliance on static IOCs alone.
Technical Details
- Attack chain: Victims are lured via SharePoint, OneDrive, or DocuSign-themed phishing pages that redirect to Microsoft's legitimate device code login portal; attackers supply their own device code, and once the victim approves it on the real Microsoft page, access and refresh tokens are issued to the attacker
- Token persistence: Obtained access and refresh tokens grant continued, legitimate-looking access to Microsoft 365 email, documents, and cloud resources, enabling long-term unauthorized access even after the initial phishing link is blocked
- Infrastructure rotation: Kali365 operators frequently rotate domains, URLs, and hosting infrastructure, causing static IOCs to expire rapidly and creating detection gaps across security controls
- Telemetry scale: ANY.RUN records 80+ public sandbox sessions weekly linked to the campaign, with activity spanning manufacturing, technology, healthcare, government, consulting, and MSSP sectors in the US
- Detection challenge: Because the authentication step occurs on Microsoft's real portal, network and endpoint signals may appear normal, shifting the burden of detection to pre-authentication indicators like lure pages, redirects, browser behavior, and attacker-controlled infrastructure
Industry Insight
- Security teams should prioritize behavioral and contextual detection over signature-based blocking for OAuth phishing campaigns; integrating live threat intelligence feeds (STIX/TAXII) into SIEM/SOAR pipelines is essential to keep pace with rotating infrastructure
- Tier 1 SOC analysts need interactive sandbox tools with AI-generated reports to rapidly validate suspicious authentication flows before tokens are fully exploited, reducing mean time to detect and contain
- Organizations should implement conditional access policies and device compliance checks that flag unusual device code approvals, and consider user awareness training specifically targeting the "approve this device code" social engineering pattern
Disclaimer: The above content is generated by AI and is for reference only.