Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts
Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device (TL-2026-1641), also tracked as Kali365 PhaaS, is a high-severity phishing campaign, first published 2026-07-22. It is attributed to Kali365 PhaaS operators (Russia) with low confidence, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 Device Authorization, maps to 18 MITRE ATT&CK techniques (T1078.004, T1087.004, T1098), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1641
- Threat ID
- TL-2026-1641
- Also known as
- Kali365 PhaaS, OAuth device code phishing, device code flow attack
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- Kali365 PhaaS operators
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- mssp, manufacturing, technology, government administration, health, consulting, financial-services, insurance, education, ngo, it-services, defense
- Target regions
- united states of america, North America, Europe, EMEA, australia, new zealand, Africa, Middle East
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
Malware and tooling: Kali365, Kali365 PhaaS panel
Kali365, a Telegram-distributed phishing-as-a-service platform active since April 2026, abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to hijack Microsoft 365 accounts without stealing passwords. Victims are directed to Microsoft's authentic device login portal (microsoft.com/devicelogin) and enter an attacker-supplied code, which grants the attacker OAuth access and refresh tokens that survive password changes and bypass MFA entirely.
How Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device works
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform first observed in April 2026 and sold via Telegram channels and a reseller/affiliate network for as little as $250/month or $2,000/year. Unlike traditional credential-phishing kits that rely on lookalike domains and fake login forms, Kali365 abuses the OAuth 2.0 Device Authorization Grant flow (RFC 8628) — a legitimate mechanism designed for input-constrained devices (smart TVs, IoT, CLI tools). The kit sends phishing emails and messages impersonating trusted cloud services (SharePoint, OneDrive, Teams, Outlook, Voicemail, Adobe Acrobat Sign, DocuSign) that instruct the victim to visit Microsoft's genuine device login page (https://microsoft.com/devicelogin) and enter an attacker-generated device code. Because the victim lands on Microsoft's real, correctly-certificated domain and performs a normal-looking authentication (including satisfying their own MFA), there is no lookalike domain, no credential-harvesting form, and no suspicious redirect for conventional phishing detection to catch. Once the victim approves the device code, the OAuth authorization server issues access and refresh tokens to the attacker-controlled application/device rather than the victim's device. These tokens grant the attacker persistent, MFA-bypassing access to the victim's mailbox, SharePoint, and OneDrive content that survives password resets and remains valid until explicitly revoked.
Deobfuscated Kali365 JavaScript shows a structured toolkit: a bot/verification gate (to filter automated scanners and sandboxes from real victims), a phishing-page deployment module, a live poll against a `/api/status/` endpoint tracking session states of `captured`, `expired`, and `declined`, and a library of lure-template generators themed as OneDrive, SharePoint, Teams, Outlook, and Voicemail notifications, plus a parallel Google device-code authentication flow for targeting Google Workspace accounts. The kit also ships AI-generated lure content in at least 15 languages, lowering the barrier for non-English-speaking affiliates. A secondary "Cookie Link" adversary-in-the-middle (AitM) capability uses a reverse proxy to transparently relay victims through attacker infrastructure, capturing session cookies and tokens even after the victim completes legitimate MFA challenges.
Post-compromise, the platform automates account takeover persistence: on receipt of captured tokens it can silently create malicious Outlook inbox rules that reroute or suppress incoming mail containing security-alert keywords (hiding password-reset notices and suspicious-sign-in warnings from the victim), register attacker devices into the victim's Entra ID tenant, and pivot to sending further internal phishing from the now-trusted compromised mailbox. ANY.RUN sandbox telemetry recorded more than 80 public interactive-analysis sessions per week tied to Kali365 samples, and observed a cluster of phishing pages hosted on `.de` ccTLD infrastructure. Documented targeting spans MSSPs, manufacturing, technology, government, healthcare, consulting, financial services, insurance, and education across North America, Europe, EMEA, Australia, and New Zealand — essentially any organization that relies on Microsoft 365.
Kali365's technique is not novel in isolation: Microsoft's own threat intelligence team documented the same OAuth device-code abuse technique from the Russia-aligned actor Storm-2372, active since at least August 2024, which used Teams/WhatsApp/Signal rapport-building lures and fake meeting invitations to harvest device codes from government, NGO, IT services, defense, telecom, health, higher-education, and energy-sector targets across Europe, North America, Africa, and the Middle East. Storm-2372 later escalated by abusing the Microsoft Authentication Broker client ID to acquire Primary Refresh Tokens (PRTs) and register attacker devices directly in Entra ID for sustained access, then used Microsoft Graph API searches for keywords such as "password," "credentials," "admin," "teamviewer," "anydesk," and "secret" to locate and exfiltrate sensitive email. Kali365 commoditizes this same device-code-abuse tradecraft into an affordable, turnkey criminal PhaaS offering usable by low-skill affiliates, dramatically expanding the pool of operators employing this MFA-bypass technique. The FBI/IC3 issued a public service announcement (I-052126-PSA, May 21 2026) specifically naming Kali365 and recommending organizations create Conditional Access policies to block device code flow entirely except for narrowly scoped, audited exceptions.
MITRE ATT&CK techniques used in TL-2026-1641
Initial Access
T1078.004 Cloud Accounts; T1566.002 Spearphishing Link
Discovery
T1087.004 Cloud Account; T1538 Cloud Service Dashboard
Persistence
T1098 Account Manipulation; T1098.005 Device Registration
Command and Control
Collection
T1114.002 Remote Email Collection; T1119 Automated Collection
Credential Access
T1528 Steal Application Access Token
Lateral Movement
Exfiltration
T1537 Transfer Data to Cloud Account
lateral-movement
T1550.001 Application Access Token
defense-impairment
T1556 Modify Authentication Process
Resource Development
T1583.001 Domains; T1587.001 Malware
Reconnaissance
reconnaissance
Affected products and versions in Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
- Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 Device Authorization Grant)
Vulnerable versions: cloud service - all tenants with device code flow enabled
Fixed in: mitigated by disabling device code flow via Conditional Access - Google — Google Workspace (device-code authentication flow)
Vulnerable versions: cloud service - tenants with device code sign-in enabled
Remediation for Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
Immediate actions
- Create a Conditional Access policy in Microsoft Entra ID to block the device code authorization flow tenant-wide, with only narrowly scoped, audited exceptions
- Review and revoke refresh tokens and active sessions for any user suspected of entering an unsolicited device code
- Audit Entra ID sign-in logs for device code authentication events with anomalous IP address, geolocation, or timing
- Review registered/joined devices in Entra ID and remove any unrecognized device registrations
- Audit Outlook inbox rules across the tenant for newly created rules that suppress or reroute mail containing security-alert keywords
- Block authentication transfer / cross-device sign-in policies between desktop and mobile where not explicitly required
Workarounds
- Where device code flow cannot be fully disabled (e.g., legitimate CLI/IoT sign-in use cases), scope Conditional Access exceptions to specific named applications and trusted network locations only
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys) tenant-wide
- Implement sign-in risk-based Conditional Access policies in Entra ID Protection
- Restrict application consent and device-enrollment permissions to reduce blast radius of stolen tokens
- Deploy Microsoft Sentinel / Defender for Office 365 detection content for device-code flow abuse and anomalous Graph API activity
- Establish an emergency-access ('break-glass') account exception process before disabling device code flow tenant-wide, to avoid legitimate input-constrained-device lockouts
- User awareness training specifically covering device-code phishing, since it presents no lookalike domain, fake form, or suspicious redirect
Weaknesses (CWE) in Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
CWE-294, CWE-287
Timeline of Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
- Storm-2372, a Russia-aligned actor, begins device-code phishing operations against government, NGO, IT services, defense, telecom, health, higher-education, and energy sector targets using Teams/WhatsApp/Signal rapport-building lures.
- Microsoft Threat Intelligence publicly discloses the Storm-2372 device code phishing campaign, including its escalation to Primary Refresh Token theft via the Microsoft Authentication Broker client ID.
- Cloud Security Alliance publishes a research note reporting OAuth device code phishing has hit 340+ Microsoft 365 organizations.
- Kali365 phishing-as-a-service kit first observed in the wild, distributed via Telegram channels with a subscription/reseller affiliate model.
- Malwarebytes publishes consumer-facing coverage of Kali365 warning users never to enter device codes at Microsoft login pages unless they personally initiated the sign-in.
- FBI/IC3 issues Public Service Announcement I-052126-PSA specifically naming Kali365 and recommending Conditional Access policies to block device code flow tenant-wide.
- ANY.RUN publishes a detailed PhaaS overview of Kali365, including deobfuscated JavaScript analysis of the /api/status/ polling mechanism and lure-template generator library.
- TL-Intel-Harness HUNT phase ingests the Kali365 campaign from Cyber Security News RSS feed and opens threat TL-2026-1641 for research.
- Cyber Security News reports more than 80 public ANY.RUN sandbox sessions per week tied to Kali365, targeting MSSP, manufacturing, technology, government, healthcare, and consulting sectors in the U.S.
Sources cited for Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
- Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts
- Kali365 Malware Analysis, Overview by ANY.RUN
- Kali365: PhaaS Overview
- FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required
- Kali365 phishing kit bypasses MFA and steals Microsoft logins
- Kali365: The New Phishing Kit Hijacking Microsoft 365 Tokens
- Internet Crime Complaint Center (IC3) PSA260521 — Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
- FBI Warns of Kali365 Phishing Kit Hijacking Microsoft 365
- Storm-2372 conducts device code phishing campaign
- Storm-2372 Launches Device Code Phishing Campaign Targeting Microsoft 365 Accounts
- Hackers Hijack Microsoft Entra Accounts via Device Code Phishing
- Storm-2372: Russia-Linked Hackers Exploit Microsoft 365 Device Code Phishing for Account Takeovers
- Defending against evolving identity attack techniques
- OAuth Device Code Phishing Hits 340+ Microsoft 365 Organizations
- The Device Code Vulnerability: Storm-2372's Blueprint for Bypassing MFA Through Microsoft's Own Authentication
Threats related to Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device
- Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA
- ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS)
Detection coverage for TL-2026-1641
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1641 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.