Kali365 targets Microsoft 365 auth

- Security researchers said on August 5 that a phishing kit called Kali365 abuses Microsoft’s device code flow to access Microsoft 365 accounts. - ANY.RUN said it records more than 80 public sessions tied to the campaign each week, with the United States the main target. - Microsoft documents say device code flow can be blocked or restricted through Entra Conditional Access and security defaults. (thehackernews.com)

Security researchers said a phishing kit called Kali365 is using Microsoft’s device code authentication flow to gain access to Microsoft 365 accounts at U.S. organizations. The campaign does not rely on a fake Microsoft password page. Instead, victims are pushed to approve an attacker-generated device code on Microsoft’s legitimate sign-in page, after which access and refresh tokens can be issued for email, files and other cloud resources. (thehackernews.com) ### How does Kali365 get in without stealing a password directly? Microsoft’s device authorization grant is designed for input-constrained devices such as smart TVs, printers and other shared or limited-input hardware. In that flow, a user enters a short code on a separate browser session to complete sign-in. Microsoft says the mechanism is legitimate, but it can be abused if a victim is tricked into authorizing a code created by an attacker. (thehackernews.com) The Hacker News reported on August 5 that Kali365 is built around that exact step. The victim sees a real Microsoft login page, which can make the prompt look routine, while the attacker receives tokens after the code is approved. Those tokens can allow continued access to Microsoft 365 resources without the attacker ever collecting the user’s password through a spoofed page. ### Why are researchers focusing on the device code flow now? (learn.microsoft.com) Microsoft said in February 2025 that a threat actor it tracks as Storm-2372 had already run a successful device code phishing campaign, and in April 2026 it described a newer AI-enabled version that automated code generation and post-compromise activity. That places Kali365 inside a broader pattern rather than as a one-off technique. (thehackernews.com) The Hacker News said ANY.RUN telemetry shows more than 80 public sessions linked to Kali365 each week, with the United States emerging as the main geographic target. A separate March 2026 report from The Hacker News said device code phishing had already hit more than 340 Microsoft 365 organizations across five countries, underscoring how widely the method has been used this year. ### What can attackers reach once a victim approves the code? (microsoft.com) The Hacker News said Kali365 can expose Microsoft 365 email, documents and cloud resources once access and refresh tokens are issued. Microsoft’s April 2026 research on device code phishing said these campaigns are designed for account compromise and sustained post-compromise access, not just initial entry. Microsoft’s March 2026 research on OAuth abuse described a related pattern in which attackers use legitimate authorization behavior to move victims into trusted login flows. (thehackernews.com) In practice, that means defenders may see a real Microsoft page in the chain even though the overall interaction began with a phishing lure. ### What does Microsoft recommend organizations do about it? (thehackernews.com) Microsoft’s Entra documentation says device code flow is one of the authentication flows that Conditional Access can explicitly target. The company also says organizations can create policies to block device code flow and authentication transfer, or scope exceptions only to accounts and scenarios that require it. Microsoft’s security defaults guidance says tenants with security defaults enabled block authentication requests that use device code flow. (microsoft.com) For organizations that still need the flow for Teams devices or developer tools, Microsoft recommends tightly scoped exceptions, sign-in log review and report-only testing before enforcement. ### Where does this leave Microsoft 365 defenders this week? August 5 is the date of the Kali365 disclosure cited by The Hacker News, and Microsoft’s current guidance is already published in Entra and Security Blog documentation. (learn.microsoft.com) Security teams can verify whether device code flow is in use, review Entra sign-in logs, and decide whether to block it tenant-wide or limit it to named accounts and approved device scenarios. (thehackernews.com) (learn.microsoft.com)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.