AI Security AI安全 7h ago Updated 1h ago 更新于 1小时前 46

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Kali365利用微软认证针对美国企业:新型企业风险

Kali365 is a device code phishing kit that abuses legitimate Microsoft authentication to steal access and refresh tokens from US organizations The attack follows a three-stage chain: SharePoint/OneDrive-themed lure → redirect to Microsoft's real device login portal → OAuth token theft ANY.RUN telemetry shows 80+ public sessions weekly, with the US as the primary target across manufacturing, healthcare, government, and MSSPs Because authentication occurs on Microsoft's legitimate page, the activi Kali365利用微软设备码认证机制实施钓鱼攻击,通过诱饵页面引导受害者输入攻击者控制的设备码,从而窃取访问和刷新令牌 攻击流程分为三阶段:诱饵(伪装SharePoint/OneDrive等可信服务)→微软认证(重定向至合法登录页面)→OAuth访问(获取持续访问权限) 攻击主要针对美国企业,每周产生80+公开沙箱会话,可导致数据泄露、财务欺诈、运营中断及合规风险 传统邮件过滤已无法有效防御,需结合实时威胁情报、交互式沙箱分析和主动威胁狩猎构建多层防御体系

70
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Kali365 is a device code phishing kit that abuses legitimate Microsoft authentication to steal access and refresh tokens from US organizations
  • The attack follows a three-stage chain: SharePoint/OneDrive-themed lure → redirect to Microsoft's real device login portal → OAuth token theft
  • ANY.RUN telemetry shows 80+ public sessions weekly, with the US as the primary target across manufacturing, healthcare, government, and MSSPs
  • Because authentication occurs on Microsoft's legitimate page, the activity appears routine, delaying detection and enabling prolonged unauthorized access
  • Defense requires expanding beyond email filtering with live threat intelligence feeds, Tier 1 sandbox analysis, and proactive threat hunting using TI Lookup queries

Why It Matters

Kali365 represents an evolving class of OAuth-based phishing that bypasses traditional email security by leveraging Microsoft's own authentication infrastructure, making detection significantly harder for SOC teams. For US organizations, a single compromised account can cascade into financial fraud, data exfiltration, and operational disruption with delayed visibility. This campaign underscores the critical need for behavioral detection and threat intelligence integration rather than reliance on static IOCs alone.

Technical Details

  • Attack chain: Victims are lured via SharePoint, OneDrive, or DocuSign-themed phishing pages that redirect to Microsoft's legitimate device code login portal; attackers supply their own device code, and once the victim approves it on the real Microsoft page, access and refresh tokens are issued to the attacker
  • Token persistence: Obtained access and refresh tokens grant continued, legitimate-looking access to Microsoft 365 email, documents, and cloud resources, enabling long-term unauthorized access even after the initial phishing link is blocked
  • Infrastructure rotation: Kali365 operators frequently rotate domains, URLs, and hosting infrastructure, causing static IOCs to expire rapidly and creating detection gaps across security controls
  • Telemetry scale: ANY.RUN records 80+ public sandbox sessions weekly linked to the campaign, with activity spanning manufacturing, technology, healthcare, government, consulting, and MSSP sectors in the US
  • Detection challenge: Because the authentication step occurs on Microsoft's real portal, network and endpoint signals may appear normal, shifting the burden of detection to pre-authentication indicators like lure pages, redirects, browser behavior, and attacker-controlled infrastructure

Industry Insight

  • Security teams should prioritize behavioral and contextual detection over signature-based blocking for OAuth phishing campaigns; integrating live threat intelligence feeds (STIX/TAXII) into SIEM/SOAR pipelines is essential to keep pace with rotating infrastructure
  • Tier 1 SOC analysts need interactive sandbox tools with AI-generated reports to rapidly validate suspicious authentication flows before tokens are fully exploited, reducing mean time to detect and contain
  • Organizations should implement conditional access policies and device compliance checks that flag unusual device code approvals, and consider user awareness training specifically targeting the "approve this device code" social engineering pattern

TL;DR

  • Kali365利用微软设备码认证机制实施钓鱼攻击,通过诱饵页面引导受害者输入攻击者控制的设备码,从而窃取访问和刷新令牌
  • 攻击流程分为三阶段:诱饵(伪装SharePoint/OneDrive等可信服务)→微软认证(重定向至合法登录页面)→OAuth访问(获取持续访问权限)
  • 攻击主要针对美国企业,每周产生80+公开沙箱会话,可导致数据泄露、财务欺诈、运营中断及合规风险
  • 传统邮件过滤已无法有效防御,需结合实时威胁情报、交互式沙箱分析和主动威胁狩猎构建多层防御体系

为什么值得看

本文揭示了利用合法认证流程的新型钓鱼攻击模式,对安全从业者具有重要警示意义。攻击者通过设备码钓鱼绕过传统邮件过滤,凸显了零信任架构下身份认证环节的关键风险。文章提供的防御框架为应对类似高级钓鱼攻击提供了可操作的实践路径。

技术解析

  • 设备码钓鱼机制:Kali365通过模仿SharePoint/OneDrive等可信服务页面,诱导受害者输入攻击者控制的设备码。当用户在微软合法认证页面完成验证后,攻击者即可获得访问令牌和刷新令牌,实现持续访问Microsoft 365资源
  • 三阶段攻击流程:第一阶段为诱饵投递(使用SharePoint主题钓鱼页面);第二阶段为重定向至微软设备登录门户;第三阶段为OAuth令牌获取,攻击者利用刷新令牌维持长期访问权限
  • 威胁情报整合方案:ANY.RUN通过STIX/TAXII协议、API和SDK将新鲜IOCs推送至SIEM/SOAR/TIP系统,支持告警富化、回溯搜索和阻断决策。情报来源覆盖15,000+组织和600,000名安全专业人员
  • 交互式沙箱分析:结合手动交互与自动化分析,可在60秒内还原完整攻击链。系统生成包含 verdict、IOCs、TTPs 和行为证据的AI摘要报告,帮助Tier 1分析师快速确认恶意活动并支持快速移交

行业启示

  • 防御范式转变:传统基于签名的邮件过滤已无法应对利用合法认证流程的钓鱼攻击,安全架构需向行为分析、威胁情报驱动和零信任身份验证转型
  • 响应时效性关键:攻击者利用合法认证页面使活动看似正常,延迟检测将扩大影响范围。安全团队需建立快速验证机制,将响应窗口从小时级缩短至分钟级
  • 行业定向威胁情报价值:针对美国企业的攻击呈现制造业、科技、医疗、政府等特定行业集中特征。建议结合地域和sector数据优化威胁狩猎策略,提前识别关联基础设施和攻击模式

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究