Kali365 Tricks Staff Into Approving Microsoft Access

Hack Read · Medium sophistication
Last updated August 5, 2026

Researchers report Kali365 is actively targeting US organizations using “device code phishing” that sends victims through Microsoft’s real login flow. Instead of stealing passwords directly, the attacker gets OAuth access and refresh tokens after the user approves a code, enabling ongoing access to Microsoft 365 email and files with fewer obvious phishing signs.

Key findings

  • Kali365 is a Phishing-as-a-Service platform using device code phishing to abuse Microsoft’s legitimate authentication flow.
  • Victims are redirected to Microsoft’s real device login portal and enter an attacker-provided code, making the activity look trustworthy.
  • Attackers aim to obtain OAuth access and refresh tokens, potentially enabling continued access to Microsoft 365 resources without the victim’s password.
  • ANY.RUN telemetry indicates sustained activity primarily targeting US organizations and spanning multiple industries (manufacturing, technology, healthcare, government, consulting, MSSPs).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, HR, IT.
  • Affected industries: Manufacturing, Technology, Healthcare, Government, Consulting, Managed Security Service Providers (MSSPs).
  • Attack channels: website.
  • Impersonated: SharePoint, DocuSign.

Awareness takeaways

  • Treat unexpected “device code” login prompts as high risk, only enter device codes you personally initiated.
  • Don’t assume a login is safe just because it’s on a real Microsoft page; the danger can be what you approve (tokens/access), not where you type the password.
  • Be extra cautious with document-themed lures (SharePoint/OneDrive/DocuSign) and verify unexpected file-share or signature requests via a known, separate channel.

Red flags to watch for

  • You are asked to enter a code you did not request
  • The flow is unusual for viewing a shared document (device-code login)
  • The initial page is a lure even though the final login page is real Microsoft
  • Unexpected signature request
  • Device-code login appears during routine document signing
  • No clear reason a code is needed to view/sign the document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this: “A document was shared with you in SharePoint. Continue to Microsoft device login and enter this code.” Looks normal, right? This is Kali365’s device code phishing. You click, and it sends you to the real Microsoft device login page. You type the code, sign in like usual, and they grab OAuth tokens to your email and files without ever stealing your password. Here’s the trap: the Microsoft page is real, but the code isn’t. You never asked for it. For a simple shared file or DocuSign review, being forced into a device-code login is weird, that’s your red flag. If you see a device code prompt you didn’t start yourself, stop. Don’t enter the code, close it and report it to security.

Similar attacks

DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026
DocuSign Phish Uses “Blob” Pages in Your Browser

DocuSign Phish Uses “Blob” Pages in Your Browser

Researchers described a real phishing campaign where victims click through legitimate Microsoft services and end up on a fake login page that is generated inside their own browser. The phishing page uses a temporary “blob URL” (not a normal website) and can disappear after the session, making it…

September 10, 2026
Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Blob URL Phish Hides Page Inside Your Browser

Blob URL Phish Hides Page Inside Your Browser

Barracuda observed a real phishing campaign that avoids hosting a traditional fake website. Instead, victims are led through Microsoft Teams to load a resource that their browser converts into a “blob URL,” rendering the phishing page only inside the victim’s browser, making it harder for scanners…

September 9, 2026
NovaCookies Sells MFA-Bypassing M365 Session Hijack

NovaCookies Sells MFA-Bypassing M365 Session Hijack

A commercial phishing service called NovaCookies is being marketed as a subscription that can hijack Microsoft 365 sessions even when MFA is enabled. Research describes how it uses legitimate-looking delivery (e.g., real DocuSign envelopes and trusted redirect endpoints) to trick users into…

September 8, 2026