Kali365 Phishing Kit Exploits Microsoft Device Codes to Hijack M365 Accounts

A sophisticated phishing kit named Kali365 is actively targeting U.S. organizations by exploiting Microsoft’s device code authentication process to compromise Microsoft 365 (M365) accounts. This method leverages legitimate Microsoft features, making detection and prevention more challenging.

Understanding Device Code Phishing

Device code phishing manipulates Microsoft’s device authorization flow, originally designed for devices with limited input capabilities like smart TVs and IoT devices. In this attack, victims receive phishing messages—often disguised as SharePoint or document-sharing requests—that prompt them to visit Microsoft’s legitimate device login portal and enter a provided code. This process inadvertently grants attackers OAuth access tokens, allowing unauthorized access to M365 services without the need for direct password theft.

Attack Methodology

The attack begins with a phishing email containing a lure related to document sharing. The email directs the recipient to a phishing page displaying a device code and instructs them to visit Microsoft’s device login portal. Upon entering the code and authenticating, the victim unknowingly authorizes an attacker-controlled application. This grants the attacker access tokens, enabling them to access corporate emails, SharePoint files, OneDrive data, and other cloud services. Notably, even if the victim changes their password, the attacker may retain access through refresh tokens until they are revoked.

Targeted Sectors and Indicators

According to telemetry from malware analysis platforms, Kali365 primarily targets organizations in the United States across various sectors, including managed security service providers, manufacturing, technology, government, healthcare, and consulting firms. The phishing pages often use the .de top-level domain, which, while not inherently malicious, should prompt scrutiny when associated with unexpected M365-related communications.

Implications and Mitigation Strategies

Token-based phishing attacks like those executed by Kali365 can lead to significant financial and operational consequences. Compromised M365 accounts may be exploited for business email compromise, invoice fraud, data theft, and internal spear-phishing. The use of legitimate Microsoft authentication pages in these attacks can delay detection, providing attackers ample time to exfiltrate data and establish persistence.

To mitigate such threats, organizations should implement phishing-resistant multi-factor authentication methods, such as FIDO2 security keys, and educate employees about the risks of device code phishing. Monitoring for unusual login patterns and promptly revoking suspicious OAuth tokens are also crucial steps in defending against these sophisticated attacks.

The emergence of Kali365 underscores the evolving nature of phishing tactics, highlighting the need for continuous vigilance and adaptive security measures to protect organizational assets.