Kali365 OAuth Phish Bypasses Password Theft

Cloud Security Alliance · High sophistication
Last updated September 8, 2026

The article describes an FBI-warned phishing operation (Kali365) that tricks Microsoft 365 users into approving access via a real Microsoft device-code login flow, often without stealing a password. Victims are lured with document-sharing themed emails and prompted to enter a device code, unintentionally granting attackers access through legitimate authentication steps.

Key findings

  • Kali365 targets Microsoft's OAuth device authentication flow (device code sign-in), which is a legitimate login method.
  • The lure uses emails that look like they come from trusted document-sharing services and asks the victim to enter a device code to view shared content.
  • Victims may complete MFA successfully because the authentication flow is real; the attacker succeeds by manipulating trust in the process.
  • The platform is described as Phishing-as-a-Service with features like AI-generated emails, campaign automation, dashboards, and OAuth token capture, lowering the skill barrier for attackers.

Who’s being targeted

  • Commonly targeted roles: All staff, Executives, HR, Finance, IT helpdesk, IT administrators, Security team.
  • Affected industries: All sectors using Microsoft 365 / cloud SaaS and identity providers.
  • Attack channels: email, website.
  • Impersonated: Trusted document-sharing service (via a Microsoft sign-in workflow).

Awareness takeaways

  • Train staff that “real” login screens can still be part of a scam, verify sign-in prompts you didn’t initiate.
  • Treat device-code login requests as high-risk and require extra verification before proceeding (especially when initiated from an email).
  • Emphasize that MFA success doesn’t always mean safety, attackers can trick users into authorizing access on their behalf.
  • Prepare for more frequent, scalable identity-focused phishing because advanced tooling is being sold as a service.

Red flags to watch for

  • Unexpected request to enter a "device code" just to view a shared document
  • Email appears to be from a document-sharing service but pushes you into an authentication flow you didn’t initiate
  • You are asked to approve/complete sign-in steps that grant access rather than simply viewing a file
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “A document has been shared with you. Enter this Microsoft device code to view it.” Looks normal, right? Behind that email is Kali365, a phishing-as-a-service kit that abuses Microsoft’s real OAuth device-code login. You type the code, see the genuine Microsoft 365 screen, even pass MFA, and you just granted them access. Here’s the twist: nothing looks fake. The login and MFA are real. The only weird thing is the setup, an email about a shared file pushing you to enter a random device code and approve access, instead of just opening the document. If an email about a shared file ever asks you to enter a Microsoft device code, stop. Don’t type it, report the message to Security right away.

Categories

Similar attacks

DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026
“Half-Click” Zimbra Email Attack Steals 90 Days

“Half-Click” Zimbra Email Attack Steals 90 Days

CISA warns a Russian state-sponsored group (“Laundry Bear,” tracked by Microsoft as “Void Blizzard”) is compromising some unpatched Zimbra email accounts when users merely open or preview a specially crafted email. The hidden code can steal passwords, MFA-related tokens, and up to 90 days of…

August 14, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Hidden ChatGPT Tasks Leak Data Across Accounts

Hidden ChatGPT Tasks Leak Data Across Accounts

Check Point researchers demonstrated a real proof-of-concept where a victim’s ChatGPT session could be tricked into running hidden, attacker-controlled tasks in parallel with the user’s normal request. In the demo, the attacker used a covert cross-account channel to make ChatGPT access the victim’s…

September 8, 2026
Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026