Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.

Listen to this article

0:00

Press play to start listening

Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.

Kali365, a Phishing-as-a-Service (PaaS) platform, is targeting US companies with device code phishing that abuses Microsoft’s legitimate authentication process. The attack comes just a few months after the FBI warned that Kali365 was targeting Microsoft 365 accounts.

By obtaining OAuth (Open Authorization) access and refresh tokens, attackers may gain continued access to corporate email, documents, and cloud services without directly stealing a password. For businesses, a single successful authorization can lead to data exposure, financial fraud, operational disruption, and higher incident response costs.

US Companies Are Kali365’s Primary Target

ANY.RUN telemetry shows that the United States is the main geographic target of Kali365. More than 80 public sessions linked to the phishing kit appear in the ANY.RUN database each week, indicating sustained activity against US companies.

Security teams can explore this activity in ANY.RUN Threat Intelligence Lookup using the following query: 

threatName:”kali365″ AND submissionCountry:”US”

Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Kali365 activity targeting US organizations revealed in ANY.RUN Threat Intelligence Lookup

The results reveal related sandbox sessions, phishing domains, URLs, infrastructure, screenshots, and targeting patterns. They also show activity across industries including manufacturing, technology, healthcare, government, consulting, and MSSPs.

Give your SOC earlier visibility into threats and the context needed to respond faster.
Reduce investigation time, limit exposure, and make confident security decisions.
Strengthen Threat Intelligence

Why Kali365 Is Difficult to Detect

Kali365 does not rely on a conventional fake login page. Victims are redirected to Microsoft’s legitimate device login portal, where they enter an attacker-provided code and complete the usual authentication process.

Because the password is entered on Microsoft’s website, the activity may appear trustworthy to both the user and some security controls. The real risk comes from the OAuth access and refresh tokens issued after the victim approves the request.

This leaves fewer obvious phishing indicators and can delay detection. By the time the activity is confirmed, attackers may already have accessed corporate email, cloud files, or other Microsoft 365 resources.

How Kali365 Gains Access to Microsoft 365

A search for threatName:”kali365” in ANY.RUN Threat Intelligence Lookup surfaces related investigations and the sandbox sessions where the activity was observed.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data
ANY.RUN’s TI Lookup displays all the relevant sandbox sessions for deeper investigations

Lure: The attack begins with a phishing page impersonating a trusted service such as SharePoint, OneDrive, or DocuSign. Kali365 includes 34 lure templates that operators can switch between for different phishing scenarios.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data
SharePoint-themed lure exposed inside ANY.RUN sandbox

Microsoft device login: After interacting with the lure, the victim is directed to Microsoft’s legitimate device login page, where they enter an attacker-provided code and complete the authentication process.

OAuth token access: Once the victim successfully authenticates, attackers obtain the OAuth access and refresh tokens issued to the application or client that initiated the device-code flow. These tokens may provide continued access to Microsoft 365 email, documents, and cloud resources without directly stealing the victim’s password.

Recommendations for Defending Against Kali365

To reduce the risk of Kali365 and similar phishing campaigns, security teams should connect continuous detection, fast triage, and proactive threat hunting.

1. Keep Detection Systems Updated with Fresh Phishing Intelligence

Kali365 infrastructure can change as operators rotate domains, URLs, and hosting. Relying only on indicators from a single investigation may leave gaps when the next wave appears.

Newly observed phishing IOCs should therefore be added regularly to SIEM, SOAR, TIP, firewalls, and other security controls. One way to maintain this coverage is through ANY.RUN Threat Intelligence Feeds, which deliver indicators through STIX/TAXII, API, or SDK.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data
TI Feeds enrich your existing system with fresh and trustworthy IOCs

The data comes from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals. Each IOC links back to the session where it was observed, helping teams verify the threat, search historical logs, and block related Kali365 infrastructure with more confidence.

2. Give Tier 1 the Context to Confirm Kali365 Faster

Kali365 is difficult to judge from the final page alone. Since victims land on Microsoft’s legitimate device login portal, the malicious lure, redirects, scripts, and backend activity can remain hidden.

A sandbox solution helps uncover the full chain behind the request. ANY.RUN’s Interactive Sandbox reveals browser activity, network connections, redirect paths, and the transition from the phishing page to Microsoft’s authentication flow.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Redirection to Microsoft’s legitimate device login page analyzed inside ANY.RUN sandbox

From there, analysts can investigate the extracted domains, URLs, and IP addresses in TI Lookup to find related sessions and connected infrastructure. This gives Tier 1 stronger evidence, speeds up triage, and keeps avoidable escalations away from senior analysts.

3. Build a More Proactive Defense

Kali365 may change its lures, infrastructure, and delivery methods over time. Waiting for a new alert to appear can leave teams reacting after the campaign has already reached the organization.

Regularly reviewing analyst-compiled research helps SOC teams spot new phishing techniques and attacker behavior earlier. ANY.RUN Threat Intelligence Reports cover current malware and phishing campaigns, with a focus on APTs and cybercriminal groups.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data
ANY.RUN’s TI Reports help with deeper investigations

The reports also include TI Lookup queries that teams can apply to threat hunting, investigation enrichment, and detection reviews. This helps defenders search for related activity in advance and prepare response actions before similar attacks cause business disruption.

Act Before Kali365 Reaches Your Environment

Kali365 shows how attackers can turn a legitimate Microsoft authentication process into unauthorized cloud access with few obvious phishing indicators. Combining identity monitoring with fresh infrastructure data and analyst-led threat research helps SOC teams detect related activity earlier, contain token abuse faster, and reduce the risk of fraud, data exposure, and operational disruption.

Organizations using ANY.RUN to investigate phishing and malware have reported:

  • Up to 21 minutes less MTTR per case, helping contain threats before they spread to more accounts, systems, or business data.
  • 94% faster threat triage, allowing teams to prioritize critical incidents and reduce alert backlogs.
  • Up to 20% less Tier 1 workload, increasing SOC capacity without adding headcount.
  • 30% fewer Tier 1-to-Tier 2 escalations, keeping senior analysts focused on incidents that require deeper expertise.

Give your SOC earlier visibility into emerging threats, reduce investigation costs, and stop phishing incidents before their business impact grows.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts