Kali365 Tricks Staff Into Approving Microsoft Access

Hack Read · Medium sophistication
Last updated August 5, 2026

Researchers report Kali365 is actively targeting US organizations using “device code phishing” that sends victims through Microsoft’s real login flow. Instead of stealing passwords directly, the attacker gets OAuth access and refresh tokens after the user approves a code, enabling ongoing access to Microsoft 365 email and files with fewer obvious phishing signs.

Key findings

  • Kali365 is a Phishing-as-a-Service platform using device code phishing to abuse Microsoft’s legitimate authentication flow.
  • Victims are redirected to Microsoft’s real device login portal and enter an attacker-provided code, making the activity look trustworthy.
  • Attackers aim to obtain OAuth access and refresh tokens, potentially enabling continued access to Microsoft 365 resources without the victim’s password.
  • ANY.RUN telemetry indicates sustained activity primarily targeting US organizations and spanning multiple industries (manufacturing, technology, healthcare, government, consulting, MSSPs).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, HR, IT.
  • Affected industries: Manufacturing, Technology, Healthcare, Government, Consulting, Managed Security Service Providers (MSSPs).
  • Attack channels: website.
  • Impersonated: SharePoint, DocuSign.

Awareness takeaways

  • Treat unexpected “device code” login prompts as high risk, only enter device codes you personally initiated.
  • Don’t assume a login is safe just because it’s on a real Microsoft page; the danger can be what you approve (tokens/access), not where you type the password.
  • Be extra cautious with document-themed lures (SharePoint/OneDrive/DocuSign) and verify unexpected file-share or signature requests via a known, separate channel.

Red flags to watch for

  • You are asked to enter a code you did not request
  • The flow is unusual for viewing a shared document (device-code login)
  • The initial page is a lure even though the final login page is real Microsoft
  • Unexpected signature request
  • Device-code login appears during routine document signing
  • No clear reason a code is needed to view/sign the document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this: “A document was shared with you in SharePoint. Continue to Microsoft device login and enter this code.” Looks normal, right? This is Kali365’s device code phishing. You click, and it sends you to the real Microsoft device login page. You type the code, sign in like usual, and they grab OAuth tokens to your email and files without ever stealing your password. Here’s the trap: the Microsoft page is real, but the code isn’t. You never asked for it. For a simple shared file or DocuSign review, being forced into a device-code login is weird, that’s your red flag. If you see a device code prompt you didn’t start yourself, stop. Don’t enter the code, close it and report it to security.

Similar attacks

N0va Phishkit Uses Trusted Apps to Steal SSO Access

N0va Phishkit Uses Trusted Apps to Steal SSO Access

A phishing kit dubbed N0va is targeting organizations in North America and Europe by impersonating familiar business services (like Microsoft Teams/SharePoint and DocuSign) and pushing victims through legitimate sign-in flows. By capturing authentication tokens rather than dropping obvious malware,…

September 16, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
DocuSign Phish Uses “Blob” Pages in Your Browser

DocuSign Phish Uses “Blob” Pages in Your Browser

Researchers described a real phishing campaign where victims click through legitimate Microsoft services and end up on a fake login page that is generated inside their own browser. The phishing page uses a temporary “blob URL” (not a normal website) and can disappear after the session, making it…

September 10, 2026