Kali365 Targets US Organizations with Data Theft via Device Code Phishing
Brief
Kali365 is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Instead of directing victims to a fake login form, the phishkit sends them to a real Microsoft page, where they authorize access using an attacker-controlled device code.
This makes the attack harder for analysts to spot and more dangerous for the business. By obtaining OAuth access and refresh tokens, attackers may gain continued access to Microsoft 365 accounts, corporate email, documents, and cloud resources without stealing the victim’s password directly.
Kali365 Attack Overview
Kali365 is a phishing kit that uses the Device Code Phishing technique. These attacks abuse Microsoft’s legitimate device authentication process: the victim isshown a user code and persuaded to enter it on the authentic Microsoft Device Login page.
