Kali365 Tricks Staff Into Approving Real Microsoft Logins

The Hacker News · Medium sophistication
Last updated August 5, 2026

Kali365 is a phishing kit that abuses Microsoft’s real “device code” sign-in flow to trick employees into approving attacker-controlled login codes. Once a victim completes authentication on Microsoft’s legitimate page, attackers can receive access and refresh tokens that may grant ongoing access to Microsoft 365 email, files, and cloud resources.

Key findings

  • Kali365 abuses Microsoft’s legitimate device login portal by having victims enter an attacker-provided device code.
  • The lure commonly impersonates trusted services like SharePoint, OneDrive, or DocuSign to start the authentication flow.
  • After the victim authenticates, attackers may obtain access and refresh tokens that can provide continued access to Microsoft 365 resources.
  • Telemetry referenced in the article indicates frequent activity and a strong focus on U.S. organizations.
  • The article highlights potential downstream impact including financial fraud (BEC/invoice manipulation), sensitive data exposure, and operational disruption.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Operations, Executive assistants, IT helpdesk / Service desk, Security operations (Tier 1 analysts).
  • Affected industries: Manufacturing, Technology, Healthcare, Government, Consulting, Managed Security Service Providers (MSSPs).
  • Attack channels: website.
  • Impersonated: SharePoint / OneDrive / DocuSign (trusted business service) and Microsoft device login.

Awareness takeaways

  • Train employees that ‘legitimate’ Microsoft login pages can still be part of a scam if they are being asked to approve or enter a code they didn’t initiate.
  • Add specific guidance for SharePoint/OneDrive/DocuSign-themed lures: don’t sign in from unexpected document prompts; navigate to the service directly via a known bookmark.
  • Coach staff to treat unexpected ‘device code’ requests as a high-risk sign-in and report them immediately to reduce the chance of token-based access persisting.

Red flags to watch for

  • You are asked to enter a code you did not request into a login flow
  • A ‘trusted’ document brand page redirects you into a device-code authentication step
  • The sign-in looks legitimate because it uses Microsoft’s real page, reducing obvious phishing signals
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you help an attacker log in to Microsoft 365… on Microsoft’s real website. Kali365 does this with a fake SharePoint or DocuSign page that says, “View document,” then sends you to Microsoft’s device login and tells you to enter a code they provide. Here’s the catch: you’re on a real Microsoft page, but it’s not your sign-in. When you enter their code and approve, you hand over access tokens to your email, OneDrive, and SharePoint. If a SharePoint, OneDrive, or DocuSign link ever tells you to enter a device code you didn’t start, stop, close it, and report it to security right away.

Similar attacks

N0va Phishkit Uses Trusted Apps to Steal SSO Access

N0va Phishkit Uses Trusted Apps to Steal SSO Access

A phishing kit dubbed N0va is targeting organizations in North America and Europe by impersonating familiar business services (like Microsoft Teams/SharePoint and DocuSign) and pushing victims through legitimate sign-in flows. By capturing authentication tokens rather than dropping obvious malware,…

September 16, 2026
N0va Device-Code Phish Steals Microsoft Sessions

N0va Device-Code Phish Steals Microsoft Sessions

Researchers reported a real phishing operation (“N0va” phishkit) that tricks people into signing into Microsoft through a legitimate Microsoft page, but for an attacker-started session. Victims can complete MFA and still grant the attacker access and refresh tokens, letting the attacker operate as…

September 11, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Russian Hackers Used AI to Evolve Phishing & Malware

Russian Hackers Used AI to Evolve Phishing & Malware

Anthropic says it disrupted a Russian state-linked campaign that used Claude to continuously rebuild malware when security tools detected it. The group (GTG-20006, linked to Midnight Blizzard/APT29) ran phishing and other human-targeted schemes, including device-code token theft against Microsoft…

September 11, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026