Back to all lessons
Awareness Lessons
2 months ago

Kali365 Abuses Microsoft Device Login Flow to Steal OAuth Tokens

The Kali365 Phishing-as-a-Service platform exploits Microsoft's legitimate device authorization flow to trick users into granting OAuth tokens to attacker-controlled applications, bypassing traditional credential theft entirely. Because the authentication occurs through Microsoft's own portal, users are less likely to recognize the attack as malicious, making security awareness a critical gap. Once an OAuth token is obtained, attackers maintain persistent access to corporate cloud services without needing passwords or triggering password-based detection controls. This matters because token-based access is often long-lived, difficult to revoke at scale, and may go undetected without specific monitoring for suspicious OAuth grants.

Tactical Insight

Immediate Actions

  • Audit and revoke all unrecognized or suspicious OAuth application grants across your Microsoft 365 tenant immediately.
  • Restrict the device code authentication flow for non-compliant or unmanaged devices using Conditional Access policies in Azure AD.

Long-term Improvements

  • Enforce Conditional Access policies that require compliant, managed devices and block legacy or unusual authentication flows by default.
  • Implement a Zero Trust model requiring continuous verification of identity and device health for all cloud service access.
  • Conduct regular security awareness training specifically covering OAuth phishing and device code flow abuse scenarios.

Detection Measures

  • Enable and monitor Azure AD sign-in logs and unified audit logs for anomalous OAuth token grants and device code authentication attempts.
  • Configure SIEM alerts for OAuth app consent events originating from unfamiliar locations, IPs, or outside business hours.
  • Integrate Microsoft Defender for Cloud Apps to detect and alert on risky OAuth application permissions in real time.