Kali365 Tricks Staff Into Approving Microsoft Access

Hack Read · Medium sophistication
Last updated August 5, 2026

Researchers report Kali365 is actively targeting US organizations using “device code phishing” that sends victims through Microsoft’s real login flow. Instead of stealing passwords directly, the attacker gets OAuth access and refresh tokens after the user approves a code, enabling ongoing access to Microsoft 365 email and files with fewer obvious phishing signs.

Key findings

  • Kali365 is a Phishing-as-a-Service platform using device code phishing to abuse Microsoft’s legitimate authentication flow.
  • Victims are redirected to Microsoft’s real device login portal and enter an attacker-provided code, making the activity look trustworthy.
  • Attackers aim to obtain OAuth access and refresh tokens, potentially enabling continued access to Microsoft 365 resources without the victim’s password.
  • ANY.RUN telemetry indicates sustained activity primarily targeting US organizations and spanning multiple industries (manufacturing, technology, healthcare, government, consulting, MSSPs).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, HR, IT.
  • Affected industries: Manufacturing, Technology, Healthcare, Government, Consulting, Managed Security Service Providers (MSSPs).
  • Attack channels: website.
  • Impersonated: SharePoint, DocuSign.

Awareness takeaways

  • Treat unexpected “device code” login prompts as high risk, only enter device codes you personally initiated.
  • Don’t assume a login is safe just because it’s on a real Microsoft page; the danger can be what you approve (tokens/access), not where you type the password.
  • Be extra cautious with document-themed lures (SharePoint/OneDrive/DocuSign) and verify unexpected file-share or signature requests via a known, separate channel.

Red flags to watch for

  • You are asked to enter a code you did not request
  • The flow is unusual for viewing a shared document (device-code login)
  • The initial page is a lure even though the final login page is real Microsoft
  • Unexpected signature request
  • Device-code login appears during routine document signing
  • No clear reason a code is needed to view/sign the document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this: “A document was shared with you in SharePoint. Continue to Microsoft device login and enter this code.” Looks normal, right? This is Kali365’s device code phishing. You click, and it sends you to the real Microsoft device login page. You type the code, sign in like usual, and they grab OAuth tokens to your email and files without ever stealing your password. Here’s the trap: the Microsoft page is real, but the code isn’t. You never asked for it. For a simple shared file or DocuSign review, being forced into a device-code login is weird, that’s your red flag. If you see a device code prompt you didn’t start yourself, stop. Don’t enter the code, close it and report it to security.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake…

July 24, 2026
Kratos Kit Used W-2 QR Phish to Hijack M365

Kratos Kit Used W-2 QR Phish to Hijack M365

Law enforcement dismantled the infrastructure behind Kratos, a widely used phishing kit that helped criminals steal Microsoft 365 credentials and, in some cases, capture session cookies to bypass MFA. The article describes a real, observed campaign using tax-themed W-2 QR-code emails that led…

July 22, 2026
Kratos PhaaS Takedown: Fake Microsoft Logins

Kratos PhaaS Takedown: Fake Microsoft Logins

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help…

July 21, 2026
M365 Device Code Phishing Bypasses User Suspicion

M365 Device Code Phishing Bypasses User Suspicion

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue login tokens directly to the attacker. Because the victim completes a legitimate MFA-approved sign-in on a legitimate Microsoft URL, the…

July 21, 2026