Kali365 Abuses Microsoft Device Login Flow to Steal OAuth Tokens
The Kali365 Phishing-as-a-Service platform exploits Microsoft's legitimate device authorization flow to trick users into granting OAuth tokens to attacker-controlled applications, bypassing traditional credential theft entirely. Because the authentication occurs through Microsoft's own portal, users are less likely to recognize the attack as malicious, making security awareness a critical gap. Once an OAuth token is obtained, attackers maintain persistent access to corporate cloud services without needing passwords or triggering password-based detection controls. This matters because token-based access is often long-lived, difficult to revoke at scale, and may go undetected without specific monitoring for suspicious OAuth grants.
Tactical Insight
Immediate Actions
- Audit and revoke all unrecognized or suspicious OAuth application grants across your Microsoft 365 tenant immediately.
- Restrict the device code authentication flow for non-compliant or unmanaged devices using Conditional Access policies in Azure AD.
Long-term Improvements
- Enforce Conditional Access policies that require compliant, managed devices and block legacy or unusual authentication flows by default.
- Implement a Zero Trust model requiring continuous verification of identity and device health for all cloud service access.
- Conduct regular security awareness training specifically covering OAuth phishing and device code flow abuse scenarios.
Detection Measures
- Enable and monitor Azure AD sign-in logs and unified audit logs for anomalous OAuth token grants and device code authentication attempts.
- Configure SIEM alerts for OAuth app consent events originating from unfamiliar locations, IPs, or outside business hours.
- Integrate Microsoft Defender for Cloud Apps to detect and alert on risky OAuth application permissions in real time.