Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts

Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device (TL-2026-1641), also tracked as Kali365 PhaaS, is a high-severity phishing campaign, first published 2026-07-22. It is attributed to Kali365 PhaaS operators (Russia) with low confidence, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 Device Authorization, maps to 18 MITRE ATT&CK techniques (T1078.004, T1087.004, T1098), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1641

Threat ID
TL-2026-1641
Also known as
Kali365 PhaaS, OAuth device code phishing, device code flow attack
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kali365 PhaaS operators
Attribution confidence
LOW
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
mssp, manufacturing, technology, government administration, health, consulting, financial-services, insurance, education, ngo, it-services, defense
Target regions
united states of america, North America, Europe, EMEA, australia, new zealand, Africa, Middle East
Detection rules
9
Indicators of compromise
21

Malware and tooling in Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

Malware and tooling: Kali365, Kali365 PhaaS panel

Kali365, a Telegram-distributed phishing-as-a-service platform active since April 2026, abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to hijack Microsoft 365 accounts without stealing passwords. Victims are directed to Microsoft's authentic device login portal (microsoft.com/devicelogin) and enter an attacker-supplied code, which grants the attacker OAuth access and refresh tokens that survive password changes and bypass MFA entirely.

How Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device works

Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform first observed in April 2026 and sold via Telegram channels and a reseller/affiliate network for as little as $250/month or $2,000/year. Unlike traditional credential-phishing kits that rely on lookalike domains and fake login forms, Kali365 abuses the OAuth 2.0 Device Authorization Grant flow (RFC 8628) — a legitimate mechanism designed for input-constrained devices (smart TVs, IoT, CLI tools). The kit sends phishing emails and messages impersonating trusted cloud services (SharePoint, OneDrive, Teams, Outlook, Voicemail, Adobe Acrobat Sign, DocuSign) that instruct the victim to visit Microsoft's genuine device login page (https://microsoft.com/devicelogin) and enter an attacker-generated device code. Because the victim lands on Microsoft's real, correctly-certificated domain and performs a normal-looking authentication (including satisfying their own MFA), there is no lookalike domain, no credential-harvesting form, and no suspicious redirect for conventional phishing detection to catch. Once the victim approves the device code, the OAuth authorization server issues access and refresh tokens to the attacker-controlled application/device rather than the victim's device. These tokens grant the attacker persistent, MFA-bypassing access to the victim's mailbox, SharePoint, and OneDrive content that survives password resets and remains valid until explicitly revoked.

Deobfuscated Kali365 JavaScript shows a structured toolkit: a bot/verification gate (to filter automated scanners and sandboxes from real victims), a phishing-page deployment module, a live poll against a `/api/status/` endpoint tracking session states of `captured`, `expired`, and `declined`, and a library of lure-template generators themed as OneDrive, SharePoint, Teams, Outlook, and Voicemail notifications, plus a parallel Google device-code authentication flow for targeting Google Workspace accounts. The kit also ships AI-generated lure content in at least 15 languages, lowering the barrier for non-English-speaking affiliates. A secondary "Cookie Link" adversary-in-the-middle (AitM) capability uses a reverse proxy to transparently relay victims through attacker infrastructure, capturing session cookies and tokens even after the victim completes legitimate MFA challenges.

Post-compromise, the platform automates account takeover persistence: on receipt of captured tokens it can silently create malicious Outlook inbox rules that reroute or suppress incoming mail containing security-alert keywords (hiding password-reset notices and suspicious-sign-in warnings from the victim), register attacker devices into the victim's Entra ID tenant, and pivot to sending further internal phishing from the now-trusted compromised mailbox. ANY.RUN sandbox telemetry recorded more than 80 public interactive-analysis sessions per week tied to Kali365 samples, and observed a cluster of phishing pages hosted on `.de` ccTLD infrastructure. Documented targeting spans MSSPs, manufacturing, technology, government, healthcare, consulting, financial services, insurance, and education across North America, Europe, EMEA, Australia, and New Zealand — essentially any organization that relies on Microsoft 365.

Kali365's technique is not novel in isolation: Microsoft's own threat intelligence team documented the same OAuth device-code abuse technique from the Russia-aligned actor Storm-2372, active since at least August 2024, which used Teams/WhatsApp/Signal rapport-building lures and fake meeting invitations to harvest device codes from government, NGO, IT services, defense, telecom, health, higher-education, and energy-sector targets across Europe, North America, Africa, and the Middle East. Storm-2372 later escalated by abusing the Microsoft Authentication Broker client ID to acquire Primary Refresh Tokens (PRTs) and register attacker devices directly in Entra ID for sustained access, then used Microsoft Graph API searches for keywords such as "password," "credentials," "admin," "teamviewer," "anydesk," and "secret" to locate and exfiltrate sensitive email. Kali365 commoditizes this same device-code-abuse tradecraft into an affordable, turnkey criminal PhaaS offering usable by low-skill affiliates, dramatically expanding the pool of operators employing this MFA-bypass technique. The FBI/IC3 issued a public service announcement (I-052126-PSA, May 21 2026) specifically naming Kali365 and recommending organizations create Conditional Access policies to block device code flow entirely except for narrowly scoped, audited exceptions.

MITRE ATT&CK techniques used in TL-2026-1641

Initial Access

T1078.004 Cloud Accounts; T1566.002 Spearphishing Link

Discovery

T1087.004 Cloud Account; T1538 Cloud Service Dashboard

Persistence

T1098 Account Manipulation; T1098.005 Device Registration

Command and Control

T1102 Web Service

Collection

T1114.002 Remote Email Collection; T1119 Automated Collection

Credential Access

T1528 Steal Application Access Token

Lateral Movement

T1534 Internal Spearphishing

Exfiltration

T1537 Transfer Data to Cloud Account

lateral-movement

T1550.001 Application Access Token

defense-impairment

T1556 Modify Authentication Process

Resource Development

T1583.001 Domains; T1587.001 Malware

Reconnaissance

T1589.002 Email Addresses

reconnaissance

T1598.004 Spearphishing Voice

Affected products and versions in Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

  • Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 Device Authorization Grant)
    Vulnerable versions: cloud service - all tenants with device code flow enabled
    Fixed in: mitigated by disabling device code flow via Conditional Access
  • Google — Google Workspace (device-code authentication flow)
    Vulnerable versions: cloud service - tenants with device code sign-in enabled

Remediation for Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

Immediate actions

  • Create a Conditional Access policy in Microsoft Entra ID to block the device code authorization flow tenant-wide, with only narrowly scoped, audited exceptions
  • Review and revoke refresh tokens and active sessions for any user suspected of entering an unsolicited device code
  • Audit Entra ID sign-in logs for device code authentication events with anomalous IP address, geolocation, or timing
  • Review registered/joined devices in Entra ID and remove any unrecognized device registrations
  • Audit Outlook inbox rules across the tenant for newly created rules that suppress or reroute mail containing security-alert keywords
  • Block authentication transfer / cross-device sign-in policies between desktop and mobile where not explicitly required

Workarounds

  • Where device code flow cannot be fully disabled (e.g., legitimate CLI/IoT sign-in use cases), scope Conditional Access exceptions to specific named applications and trusted network locations only

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys) tenant-wide
  • Implement sign-in risk-based Conditional Access policies in Entra ID Protection
  • Restrict application consent and device-enrollment permissions to reduce blast radius of stolen tokens
  • Deploy Microsoft Sentinel / Defender for Office 365 detection content for device-code flow abuse and anomalous Graph API activity
  • Establish an emergency-access ('break-glass') account exception process before disabling device code flow tenant-wide, to avoid legitimate input-constrained-device lockouts
  • User awareness training specifically covering device-code phishing, since it presents no lookalike domain, fake form, or suspicious redirect

Weaknesses (CWE) in Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

CWE-294, CWE-287

Timeline of Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

  • Storm-2372, a Russia-aligned actor, begins device-code phishing operations against government, NGO, IT services, defense, telecom, health, higher-education, and energy sector targets using Teams/WhatsApp/Signal rapport-building lures.
  • Microsoft Threat Intelligence publicly discloses the Storm-2372 device code phishing campaign, including its escalation to Primary Refresh Token theft via the Microsoft Authentication Broker client ID.
  • Cloud Security Alliance publishes a research note reporting OAuth device code phishing has hit 340+ Microsoft 365 organizations.
  • Kali365 phishing-as-a-service kit first observed in the wild, distributed via Telegram channels with a subscription/reseller affiliate model.
  • Malwarebytes publishes consumer-facing coverage of Kali365 warning users never to enter device codes at Microsoft login pages unless they personally initiated the sign-in.
  • FBI/IC3 issues Public Service Announcement I-052126-PSA specifically naming Kali365 and recommending Conditional Access policies to block device code flow tenant-wide.
  • ANY.RUN publishes a detailed PhaaS overview of Kali365, including deobfuscated JavaScript analysis of the /api/status/ polling mechanism and lure-template generator library.
  • TL-Intel-Harness HUNT phase ingests the Kali365 campaign from Cyber Security News RSS feed and opens threat TL-2026-1641 for research.
  • Cyber Security News reports more than 80 public ANY.RUN sandbox sessions per week tied to Kali365, targeting MSSP, manufacturing, technology, government, healthcare, and consulting sectors in the U.S.

Sources cited for Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

Threats related to Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device

Detection coverage for TL-2026-1641

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1641 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats