Kali365 Targets US Organizations with Data Theft via Device Code Phishing
ID: 303cfe82-d22c-56cf-9cf2-6f3c4116dddc
STIX ID: report--303cfe82-d22c-56cf-9cf2-6f3c4116dddc
Feed Name: ANY.RUN's Cybersecurity Blog
Kali365 is an active phishing kit leveraging Device Code Phishing to trick victims into approving attacker-provided device codes on legitimate Microsoft (and sometimes Google) device login pages; successful flows yield OAuth access and refresh tokens that enable persistent access to Microsoft 365 resources without stealing passwords. ANY.RUN telemetry shows sustained U.S. targeting across multiple industries, numerous multi-brand lure templates, specific API endpoints (/api/generate, /api/status), and a long list of domains used as infrastructure; recommended actions include token/session revocation, OAuth consent review, expanded monitoring for token-based abuse, and domain/URL IOC blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
