Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA — Threadlinqs Intelligence
As of 2026-07-21, Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-1584 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Kali365 is a Phishing-as-a-Service (PhaaS) kit, first observed in April 2026 and distributed via Telegram, that abuses the legitimate OAuth 2.0 Device Authorization Grant flow of Microsoft and Google
Kali365 is a subscription-based Phishing-as-a-Service platform (advertised at roughly US $250/month or $2,000/year on Telegram) that operationalizes device-code phishing — an OAuth 2.0 Device Authorization Grant abuse technique first weaponized at scale by the Russia-aligned threat cluster Storm-2372 (also tracked as APT29, UTA0304, UTA0307, and UNK_AcademicFlare) beginning in August 2024 and publicly documented by Microsoft and Volexity in February 2025. Kali365 packages that technique into a turnkey kit usable by non-technical operators.
The attack begins with a phishing lure — email or chat message — impersonating a trusted cloud productivity brand (OneDrive, SharePoint, Microsoft Teams, Outlook, OneNote, Google Drive, DocuSign, Adobe, and 26 additional AI-generated templates covering Microsoft Admin, Microsoft Security, Teams Meeting, Microsoft Forms, Planner, Calendar, Power Automate, Sway, Stream, Whiteboard, Bookings, Intune, Yammer, Loop, Copilot, To Do, OneDrive for Business, SharePoint News, Teams Approval, Password Reset, MFA Setup, and Quarantined Messages notifications). The lure page requests the target's phone number or email for tracking (verification gate) and then displays an authentic Microsoft- or Google-issued device code, instructing the victim to enter it at the real endpoint (login.microsoftonline.com/common/oauth2/deviceauth for Microsoft, and the equivalent Google device endpoint). Because the victim authenticates on the vendor's genuine, correctly-TLS-signed login page, no credential-harvesting page, password prompt, or MFA challenge is ever presented to them — the attack is invisible to conventional anti-phishing indicators, URL reputation, and MFA controls.
Once the victim approves the device code, Microsoft or Google issues a valid OAuth access token and refresh token to the attacker-controlled polling session. Kali365's backend polls /api/status/<number> (Microsoft flow) or /api/google/status/<number> (Google flow) until the session state transitions to "captured", at which point the platform delivers the stolen tokens to the operator's dashboard. Refresh tokens obtained this way persist across victim password resets, giving the attacker durable, MFA-bypassing access to Outlook, Teams, OneDrive, SharePoint, and other Microsoft Graph / Google Workspace resources tied to the granted application scope. Kali365 differentiates itself from earlier device-code kits with built-in post-compromise automation: on token capture it can automatically create malicious inbox rules in the compromised mailbox (a classic BEC persistence/collection technique) without further operator action, and it exposes a real-time dashboard for tracking individual targets and campaign session states (created, captured, expired, declined).
Infrastructure observed in ANY.RUN sandbox telemetry consists of dozens of freshly-registered, mostly .de and a handful of .xyz/.net/.com/.top second-level domains fronting the phishing lure pages, plus at least one Cloudflare Workers subdomain (cloud-microsoft-drive-for-business.workers.dev) used to host a Microsoft-branded lure — consistent with FBI IC3 guidance noting Kali365 operators favor disposable cloud-hosted infrastructure such as workers.dev to minimize takedown friction and blend with legitimate Microsoft-adjacent naming. Session configuration is driven by two backend parameters, design (selects which of the 34 lure templates renders) and flow_type (selects Microsoft or Google as the OAuth provider), retrievable via /api/lure-config/<ID> and generated via /api/generate?lure=<ID>.
The FBI/IC3 PSA (I-052126-PSA, 21 May 2026) recommends organizations create a Conditional Access policy in Microsoft Entra ID that blocks the device code authentication flow globally, audit legitimate business dependencies on device code flow before restricting it, disable authentication-state transfer between devices, maintain break-glass emergency access accounts excluded from the block policy, revoke
Weaknesses (CWE)
CWE-287, CWE-290, CWE-346
Target sectors: mssp, manufacturing, technology, government administration, publicadministration, health, consulting
Target regions: North America, united states of america, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589.002, T1583.001, T1587.001, T1585.001, T1566.002, T1199, T1204.001, T1098.003, T1114.003, T1550.001