[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8v2Dd__B7ZPTwocCbeELNzM-80zJVJ5xyrbJeVuW10U":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"904c49f9-2ed3-4c41-abe8-49f8ec45526b","Kali365 Exploits Microsoft Device Login to Access US Corporate Data","kali365-exploits-microsoft-device-login-to-access-us-corporate-data-304769","Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.","The Kali365 Phishing-as-a-Service platform is targeting US companies by exploiting Microsoft's legitimate device login process to obtain OAuth tokens. This method bypasses traditional password theft, allowing attackers continued access to corporate data and cloud services. Security teams face challenges in detection due to the use of Microsoft's own authentication portal.","Kali365 uses Microsoft device login to steal OAuth tokens from US companies.","Security Microsoft Phishing ScamKali365 Exploits Microsoft Device Login to Access US Corporate Data Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks. byOwais SultanAugust 5, 20264 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings. Kali365, a Phishing-as-a-Service (PaaS) platform, is targeting US companies with device code phishing that abuses Microsoft’s legitimate authentication process. The attack comes just a few months after the FBI warned that Kali365 was targeting Microsoft 365 accounts. By obtaining OAuth (Open Authorization) access and refresh tokens, attackers may gain continued access to corporate email, documents, and cloud services without directly stealing a password. For businesses, a single successful authorization can lead to data exposure, financial fraud, operational disruption, and higher incident response costs. US Companies Are Kali365’s Primary Target ANY.RUN telemetry shows that the United States is the main geographic target of Kali365. More than 80 public sessions linked to the phishing kit appear in the ANY.RUN database each week, indicating sustained activity against US companies. Security teams can explore this activity in ANY.RUN Threat Intelligence Lookup using the following query: threatName:”kali365″ AND submissionCountry:”US” Kali365 activity targeting US organizations revealed in ANY.RUN Threat Intelligence Lookup The results reveal related sandbox sessions, phishing domains, URLs, infrastructure, screenshots, and targeting patterns. They also show activity across industries including manufacturing, technology, healthcare, government, consulting, and MSSPs. Give your SOC earlier visibility into threats and the context needed to respond faster.Reduce investigation time, limit exposure, and make confident security decisions.Strengthen Threat Intelligence Why Kali365 Is Difficult to Detect Kali365 does not rely on a conventional fake login page. Victims are redirected to Microsoft’s legitimate device login portal, where they enter an attacker-provided code and complete the usual authentication process. Because the password is entered on Microsoft’s website, the activity may appear trustworthy to both the user and some security controls. The real risk comes from the OAuth access and refresh tokens issued after the victim approves the request. This leaves fewer obvious phishing indicators and can delay detection. By the time the activity is confirmed, attackers may already have accessed corporate email, cloud files, or other Microsoft 365 resources. How Kali365 Gains Access to Microsoft 365 A search for threatName:”kali365” in ANY.RUN Threat Intelligence Lookup surfaces related investigations and the sandbox sessions where the activity was observed. ANY.RUN’s TI Lookup displays all the relevant sandbox sessions for deeper investigations Lure: The attack begins with a phishing page impersonating a trusted service such as SharePoint, OneDrive, or DocuSign. Kali365 includes 34 lure templates that operators can switch between for different phishing scenarios. SharePoint-themed lure exposed inside ANY.RUN sandbox Microsoft device login: After interacting with the lure, the victim is directed to Microsoft’s legitimate device login page, where they enter an attacker-provided code and complete the authentication process. OAuth token access: Once the victim successfully authenticates, attackers obtain the OAuth access and refresh tokens issued to the application or client that initiated the device-code flow. These tokens may provide continued access to Microsoft 365 email, documents, and cloud resources without directly stealing the victim’s password. Recommendations for Defending Against Kali365 To reduce the risk of Kali365 and similar phishing campaigns, security teams should connect continuous detection, fast triage, and proactive threat hunting. 1. Keep Detection Systems Updated with Fresh Phishing Intelligence Kali365 infrastructure can change as operators rotate domains, URLs, and hosting. Relying only on indicators from a single investigation may leave gaps when the next wave appears. Newly observed phishing IOCs should therefore be added regularly to SIEM, SOAR, TIP, firewalls, and other security controls. One way to maintain this coverage is through ANY.RUN Threat Intelligence Feeds, which deliver indicators through STIX\u002FTAXII, API, or SDK. TI Feeds enrich your existing system with fresh and trustworthy IOCs The data comes from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals. Each IOC links back to the session where it was observed, helping teams verify the threat, search historical logs, and block related Kali365 infrastructure with more confidence. 2. Give Tier 1 the Context to Confirm Kali365 Faster Kali365 is difficult to judge from the final page alone. Since victims land on Microsoft’s legitimate device login portal, the malicious lure, redirects, scripts, and backend activity can remain hidden. A sandbox solution helps uncover the full chain behind the request. ANY.RUN’s Interactive Sandbox reveals browser activity, network connections, redirect paths, and the transition from the phishing page to Microsoft’s authentication flow. Redirection to Microsoft’s legitimate device login page analyzed inside ANY.RUN sandbox From there, analysts can investigate the extracted domains, URLs, and IP addresses in TI Lookup to find related sessions and connected infrastructure. This gives Tier 1 stronger evidence, speeds up triage, and keeps avoidable escalations away from senior analysts. 3. Build a More Proactive Defense Kali365 may change its lures, infrastructure, and delivery methods over time. Waiting for a new alert to appear can leave teams reacting after the campaign has already reached the organization. Regularly reviewing analyst-compiled research helps SOC teams spot new phishing techniques and attacker behavior earlier. ANY.RUN Threat Intelligence Reports cover current malware and phishing campaigns, with a focus on APTs and cybercriminal groups. ANY.RUN’s TI Reports help with deeper investigations The reports also include TI Lookup queries that teams can apply to threat hunting, investigation enrichment, and detection reviews. This helps defenders search for related activity in advance and prepare response actions before similar attacks cause business disruption. Act Before Kali365 Reaches Your Environment Kali365 shows how attackers can turn a legitimate Microsoft authentication process into unauthorized cloud access with few obvious phishing indicators. Combining identity monitoring with fresh infrastructure data and analyst-led threat research helps SOC teams detect related activity earlier, contain token abuse faster, and reduce the risk of fraud, data exposure, and operational disruption. Organizations using ANY.RUN to investigate phishing and malware have reported: Up to 21 minutes less MTTR per case, helping contain threats before they spread to more accounts, systems, or business data. 94% faster threat triage, allowing teams to prioritize critical incidents and reduce alert backlogs. Up to 20% less Tier 1 workload, increasing SOC capacity without adding headcount. 30% fewer Tier 1-to-Tier 2 escalations, keeping senior analysts focused on incidents that require deeper expertise. Give your SOC earlier visibility into emerging threats, reduce investigation costs, and stop phishing incidents before their business impact grows. ANY RUNCyber AttackCybersecurityKali365MicrosoftOAuthPaaSPhishingPhishing KitScamsecurityThreat Intelligence Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Data Fabri","https:\u002F\u002Fhackread.com\u002Fkali365-exploit-microsoft-device-login-access-us-data\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002Fkali365-exploit-microsoft-device-login-access-us-data-7.png","2026-08-05T07:39:25+00:00","2026-08-05T08:00:18.327686+00:00",8,[18,21,23,25,27,30],{"name":19,"type":20},"Microsoft 365","product",{"name":22,"type":20},"SharePoint",{"name":24,"type":20},"OneDrive",{"name":26,"type":20},"DocuSign",{"name":28,"type":29},"OAuth","technology",{"name":31,"type":32},"Kali365","threat_actor","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":33,"icon":35,"name":36,"slug":37},null,"Threat Intelligence","threat-intelligence",[39,44,49],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},[52],{"type":48,"value":31,"context":53},"Phishing-as-a-Service platform"]