logo

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

ID: 88473cb1-37f7-5fbc-be5d-81a6a2c1922e

STIX ID: report--88473cb1-37f7-5fbc-be5d-81a6a2c1922e

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Owais Sultan

...
...

Kali365 is a Phishing-as-a-Service campaign targeting US companies that uses device-code phishing to redirect victims to Microsoft’s legitimate device login, tricking them into entering attacker-provided codes so the adversary can obtain OAuth access and refresh tokens for continued access to Microsoft 365 email and cloud resources. ANY.RUN telemetry shows sustained weekly activity across multiple industries, and the report details lure templates, observed infrastructure/IOCs, and recommendations—keeping detection feeds current, using sandboxes to reveal redirect chains, and proactive threat hunting to reduce token abuse and data exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.