New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages
A newly identified phishing kit, dubbed Kali365, is targeting US organizations by exploiting a legitimate Microsoft authentication feature known as device code login. Instead of using a fake login page, attackers trick victims into entering an attacker-generated code on Microsoft's real sign-in portal. Because the page is genuine, it can bypass the usual red flags people are trained to spot, such as suspicious URLs or spoofed branding.
Once a victim approves the code, Microsoft issues access and refresh tokens to the attacker. These tokens can grant ongoing access to the victim's email, documents, and other cloud resources — often without requiring the attacker to know the victim's password. This creates a serious risk of data theft, financial fraud, and further compromise within an organization's systems, as attackers can maintain access even after the initial login session ends.
While this campaign is currently focused on US organizations, similar phishing techniques are frequently adapted for use against businesses worldwide, including in Australia. The use of legitimate authentication pages makes this type of attack particularly difficult for employees to detect through visual inspection alone.