logo

Kali365 Device-Code Phishing Turns an EFT Payment Lure into Microsoft 365 Token Theft

ID: 1d543686-5c8b-5bc2-aa50-ef2280c687db

STIX ID: report--1d543686-5c8b-5bc2-aa50-ef2280c687db

Feed Name: Blog – Hornetsecurity – Next-Gen Microsoft 365 Security

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-07-25

Author: Threat Intelligence Lab

...
...

This report analyzes a Kali365 device-code phishing campaign that uses business-themed EFT/invoice lures and multi-stage redirects (legitimate SaaS hosting → phishing landing → Microsoft device-code flow) to trick victims into authorizing attacker-controlled OAuth sessions and thereby capture Microsoft 365 access tokens; it includes observed URLs, domains, an IP address, comparisons to FBI reporting, and defensive guidance such as blocking device-code flow and inspecting redirect chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.