Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.
The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud, operational disruption, and costly incident response.
How Kali365 Targets US Organizations
Kali365 is a device code phishing kit built to abuse legitimate Microsoft authentication. ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week, with the United States emerging as its main geographic target.
One of these sandbox sessions shows a SharePoint-themed lure used to draw the victim into the authentication flow.







