Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts — Threadlinqs Intelligence
As of 2026-07-22, Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts is a high-severity phishing threat attributed to Kali365 PhaaS operators (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1641 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Kali365 PhaaS operators · Russia · FINANCIAL
Kali365, a Telegram-distributed phishing-as-a-service platform active since April 2026, abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to hijack Microsoft 365 accounts without
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform first observed in April 2026 and sold via Telegram channels and a reseller/affiliate network for as little as $250/month or $2,000/year. Unlike traditional credential-phishing kits that rely on lookalike domains and fake login forms, Kali365 abuses the OAuth 2.0 Device Authorization Grant flow (RFC 8628) — a legitimate mechanism designed for input-constrained devices (smart TVs, IoT, CLI tools). The kit sends phishing emails and messages impersonating trusted cloud services (SharePoint, OneDrive, Teams, Outlook, Voicemail, Adobe Acrobat Sign, DocuSign) that instruct the victim to visit Microsoft's genuine device login page (https://microsoft.com/devicelogin) and enter an attacker-generated device code. Because the victim lands on Microsoft's real, correctly-certificated domain and performs a normal-looking authentication (including satisfying their own MFA), there is no lookalike domain, no credential-harvesting form, and no suspicious redirect for conventional phishing detection to catch. Once the victim approves the device code, the OAuth authorization server issues access and refresh tokens to the attacker-controlled application/device rather than the victim's device. These tokens grant the attacker persistent, MFA-bypassing access to the victim's mailbox, SharePoint, and OneDrive content that survives password resets and remains valid until explicitly revoked.
Deobfuscated Kali365 JavaScript shows a structured toolkit: a bot/verification gate (to filter automated scanners and sandboxes from real victims), a phishing-page deployment module, a live poll against a `/api/status/` endpoint tracking session states of `captured`, `expired`, and `declined`, and a library of lure-template generators themed as OneDrive, SharePoint, Teams, Outlook, and Voicemail notifications, plus a parallel Google device-code authentication flow for targeting Google Workspace accounts. The kit also ships AI-generated lure content in at least 15 languages, lowering the barrier for non-English-speaking affiliates. A secondary "Cookie Link" adversary-in-the-middle (AitM) capability uses a reverse proxy to transparently relay victims through attacker infrastructure, capturing session cookies and tokens even after the victim completes legitimate MFA challenges.
Post-compromise, the platform automates account takeover persistence: on receipt of captured tokens it can silently create malicious Outlook inbox rules that reroute or suppress incoming mail containing security-alert keywords (hiding password-reset notices and suspicious-sign-in warnings from the victim), register attacker devices into the victim's Entra ID tenant, and pivot to sending further internal phishing from the now-trusted compromised mailbox. ANY.RUN sandbox telemetry recorded more than 80 public interactive-analysis sessions per week tied to Kali365 samples, and observed a cluster of phishing pages hosted on `.de` ccTLD infrastructure. Documented targeting spans MSSPs, manufacturing, technology, government, healthcare, consulting, financial services, insurance, and education across North America, Europe, EMEA, Australia, and New Zealand — essentially any organization that relies on Microsoft 365.
Kali365's technique is not novel in isolation: Microsoft's own threat intelligence team documented the same OAuth device-code abuse technique from the Russia-aligned actor Storm-2372, active since at least August 2024, which used Teams/WhatsApp/Signal rapport-building lures and fake meeting invitations to harvest device codes from government, NGO, IT services, defense, telecom, health, higher-education, and energy-sector targets across Europe, North America, Africa, and the Middle East. Storm-2372 later escalated by abusing the Microsoft Authentication Broker client ID to acquire Primary Refresh Tokens (PRTs) and register attacker devices directly in Entra ID for sustained access, then used Microsoft Graph API searches for keywo
Weaknesses (CWE)
CWE-294, CWE-287
Target sectors: mssp, manufacturing, technology, government administration, health, consulting, financial-services, insurance, education, ngo, it-services, defense
Target regions: united states of america, North America, Europe, EMEA, australia, new zealand, Africa, Middle East
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566.002, T1078.004, T1528, T1598.004, T1550.001, T1556, T1098, T1098.005, T1114.002, T1119