-
The Kali365 phishing kit is taking advantage of Microsoft’s own device authentication process to slip past MFA.
-
US organizations are the primary target. Every week, there are more than 80 public sessions logged across industries like manufacturing, tech, healthcare, government, consulting, and managed security providers.
-
Defending against Kali365 requires fresh threat intelligence, faster incident triage, and proactive threat research.

A newly identified phishing kit called Kali365 is turning a legitimate Microsoft login process into a backdoor for corporate data. The attack reportedly abuses Microsoft’s device code authentication loop to grab OAuth tokens.
With those in hand, they’re in, reading emails, digging through documents, and poking around cloud resources, all without ever needing a password. Victims don’t realize anything’s off because they’re approving the access themselves on Microsoft’s legit login page.
Kali365 surfaced in April 2O26 as a Phishing-as-a-Service platform. The FBI put out an alert in May, warning that this toolkit makes it easy for just about anyone, even folks with very little technical know-how, to break into Microsoft 365 environments.
It’s sold on Telegram for as little as $250 a month, and it’s pretty slick: buyers get AI-generated phishing lures, out-of-the-box campaign templates, and dashboards for tracking victims in real time. It’s basically a one-stop shop for launching phishing attacks at scale.
How Attackers Exploit Microsoft’s Legitimate Flow
Kali365 uses three major steps, all relying on Microsoft’s infrastructure. The first step is where the attacker lures their victim. The victim receives a lure impersonating the authentication page of trusted services like OneDrive, SharePoint, or DocuSign.
The phishing package contains thirty-four templates. This gives the attacker the freedom to pick the perfect scheme for a specific victim. After that, the lure redirects the victim to the authentic portal of Microsoft, where the target would need to enter a code sent by the perpetrator.
Finally, after the victim has typed in the code and completed the normal authentication step, the hacker’s system then captures the OAuth access and refreshes tokens. These tokens allow persistent access to the victim’s Microsoft 365 account without needing.
As the operation relies on an official Microsoft page, MFA cannot block the attack. The victim completes the MFA challenge themselves, so from Microsoft’s perspective, the session looks entirely trustworthy. This makes Kali365 particularly difficult to detect with traditional phishing defenses.
U.S. Organizations are the Primary Target
According to ANY.RUN telemetry, the United States is the main geographic target of the Kali365 campaign. More than 80 sandbox instances tied to the phishing kit are reported each week, mostly within US industries.
These attacks keep targeting organizations with Microsoft 365, hitting a wide range of industries, including manufacturing, tech, healthcare, government, consulting, and even security service providers.
According to the threat intelligence company, most Kali365 phishing pages pop up with a .de domain. This detail helps security teams identify suspicious infrastructure more quickly.
The Business Impact of a Token Breach
For US companies, a single successful Kali365 authorization can have severe consequences. When someone compromises an email account, things can go south fast.
Fraudsters mess with invoices, trick people into sending payments, and pull off business email compromises without much trouble. They often grab sensitive emails, internal files, customer data, and any confidential documents they stumble on, which means data leaks and all sorts of compliance headaches.
Because victims authenticate on a legitimate Microsoft page, the activity appears routine at first. What’s worse, it usually takes a while for anyone to notice. That delay gives attackers a chance to dig deeper into cloud resources and make a bigger mess.
The fallout? You’re looking at disrupted operations, expensive cleanup, and lasting reputational damage. The real problem here is that device code phishing isn’t some one-off threat anymore. It’s a common way attackers target the cloud authentication process itself, and companies need to take that seriously.
The scale of the data obtained through such attacks is staggering; a recent dark web listing advertised 41 million telecom customer records across the US and Europe, showing the vast market for stolen data.
Defense Priorities for Security Leaders
Defending against Kali365 requires more than email filtering. Security leaders must prioritize three key areas.
First, they need current campaign intelligence. However, because the Kali365 criminals change domains, URLs, and hosting infrastructure very fast, the indicators used for one incident may become obsolete very quickly.
Therefore, they need to integrate new phishing IOCs into the SIEM, SOAR, firewall, and other security mechanisms.
Secondly, the Tier 1 analysts require the means to verify any suspicious behavior. Since the warning signs appear in the lure, redirects, and browser behavior, interactive analysis tools can reveal the full attack chain faster. Auto-generated reports with AI summaries provide the evidence needed for faster containment.
Third, teams should turn threat research into proactive defense by exploring campaign data and using threat intelligence reports to track emerging attack patterns before they reach their environment.
Restricting or disabling device code authentication where it is not required is also a direct technical mitigation.