Kali365 is a phishing kit that abuses legitimate Microsoft authentication to gain unauthorized access to corporate data. It targets US organizations by presenting victims with a page impersonating trusted services like SharePoint or OneDrive. The victim is then redirected to Microsoft's official device login portal where they are prompted to enter an attacker-provided code.
Once the victim completes authentication by entering the code, attackers obtain access and refresh tokens. These tokens provide continued access to Microsoft 365 email, documents, and cloud resources. This method is particularly effective because the authentication occurs on Microsoft's legitimate page, making it harder for victims to detect the phishing attempt. ANY.RUN telemetry shows more than 80 public sessions linked to this campaign weekly, primarily targeting the United States.
A single approved device-code request can lead to a broader Microsoft 365 compromise. For US companies, the consequences include financial fraud through invoice manipulation or payment fraud, sensitive data exposure from accessing corporate emails and files, and operational disruption due to unauthorized access to cloud services. The subtle nature of the attack can delay detection, increasing response costs and posing compliance and reputational risks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new phishing kit named Kali365 is actively targeting US organizations by weaponizing legitimate Microsoft authentication processes. It tricks victims into approving attacker-controlled device codes on Microsoft's own login page, granting attackers continued access to Microsoft 365 resources like email and documents. This method bypasses typical phishing indicators, increasing the risk of financial fraud, data exposure, and operational disruption for affected businesses.