A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources.
Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact with an authentic Microsoft website, the attack is significantly harder to recognize and block.
Device Code Authentication Becomes the Attack Vector
Security researchers say Kali365 abuses Microsoft’s device code authentication feature, which is commonly used to sign users into devices that lack a full keyboard or browser.
Instead of stealing usernames and passwords directly, attackers generate their own device authentication code and persuade victims to enter it on Microsoft’s official login page.
Once the victim approves the request and completes authentication, Microsoft issues access and refresh tokens that can allow attackers to continue accessing the victim’s Microsoft 365 environment without needing their password.
This approach enables attackers to maintain access even after the initial phishing attempt has succeeded.

Campaign Primarily Targets U.S. Organizations
Threat intelligence data indicates that the campaign is heavily focused on organizations in the United States.
Researchers have observed numerous public attack sessions each week, suggesting the phishing operation remains active across multiple industries.
Victims are typically lured using webpages designed to resemble trusted business services such as:
- SharePoint
- OneDrive
- DocuSign
These fake portals encourage users to continue what appears to be a normal document-sharing or collaboration process before directing them to Microsoft’s legitimate login page.
How the Attack Works
Researchers say the phishing chain generally follows three stages:
- Fake business invitation Victims receive a phishing link disguised as a document-sharing or collaboration request.
- Legitimate Microsoft login Instead of presenting a counterfeit login page, the phishing site redirects users to Microsoft’s official device authentication portal and instructs them to enter a code generated by the attacker.
- Token theft After authentication is completed, attackers receive Microsoft-issued authentication tokens that can provide ongoing access to the victim’s Microsoft 365 account.
Because the login occurs through Microsoft’s genuine authentication system, many users believe the request is legitimate.
Potential Business Impact
Researchers warn that a single compromised Microsoft 365 account can quickly escalate into a broader security incident.
Possible consequences include:
- Business Email Compromise (BEC)
- Invoice and payment fraud
- Unauthorized access to confidential documents
- Theft of customer information
- Exposure of intellectual property
- Disruption of internal communications
- Increased incident response costs
- Regulatory compliance challenges following data breaches
Since attackers rely on valid authentication rather than stolen passwords, suspicious activity may remain unnoticed until damage has already occurred.
Why Traditional Email Security Isn’t Enough
Unlike conventional phishing campaigns, Kali365 does not depend on fake Microsoft login pages.
Because users authenticate through Microsoft’s legitimate infrastructure, many traditional email filters and anti-phishing tools may fail to identify the attack.
Researchers say organizations should complement email security with stronger identity protection, continuous monitoring of authentication activity, and behavioral analysis capable of detecting unusual sign-in patterns.

Improving Detection and Response
Security teams are encouraged to strengthen defenses by monitoring for suspicious device-code authentication requests and integrating current threat intelligence into existing security platforms.
Keeping indicators of compromise updated across SIEM, SOAR, firewalls, and other security tools can improve detection as attackers frequently rotate domains and infrastructure.
Researchers also recommend using sandbox analysis to safely investigate suspicious phishing links, browser activity, and redirect chains before users interact with them.
Threat Intelligence Plays a Key Role
Ongoing monitoring of phishing campaigns can help security teams identify emerging infrastructure before attacks spread throughout an organization.
Threat intelligence reports and investigation platforms provide additional context by revealing attacker infrastructure, phishing domains, targeting patterns, and tactics associated with active campaigns.
This information enables security operations centers (SOCs) to improve threat hunting and respond more quickly when similar attacks appear within their environments.

Organizations Should Strengthen Identity Security
The emergence of Kali365 highlights a growing shift in cyberattacks toward abusing trusted authentication mechanisms instead of relying solely on stolen credentials.
Organizations can reduce their exposure by:
- Educating employees about device-code phishing attacks.
- Reviewing and restricting device-code authentication where appropriate.
- Monitoring Microsoft Entra ID sign-in logs for unusual authentication activity.
- Enforcing Conditional Access policies and multifactor authentication.
- Revoking suspicious authentication tokens immediately after detecting unauthorized access.
- Continuously updating threat intelligence and detection rules.
As attackers increasingly target cloud identities rather than passwords, defending authentication workflows has become just as important as protecting endpoints and email systems.

