Kali365 Tricks Staff Into Approving Real Microsoft Logins

The Hacker News · Medium sophistication
Last updated August 5, 2026

Kali365 is a phishing kit that abuses Microsoft’s real “device code” sign-in flow to trick employees into approving attacker-controlled login codes. Once a victim completes authentication on Microsoft’s legitimate page, attackers can receive access and refresh tokens that may grant ongoing access to Microsoft 365 email, files, and cloud resources.

Key findings

  • Kali365 abuses Microsoft’s legitimate device login portal by having victims enter an attacker-provided device code.
  • The lure commonly impersonates trusted services like SharePoint, OneDrive, or DocuSign to start the authentication flow.
  • After the victim authenticates, attackers may obtain access and refresh tokens that can provide continued access to Microsoft 365 resources.
  • Telemetry referenced in the article indicates frequent activity and a strong focus on U.S. organizations.
  • The article highlights potential downstream impact including financial fraud (BEC/invoice manipulation), sensitive data exposure, and operational disruption.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Operations, Executive assistants, IT helpdesk / Service desk, Security operations (Tier 1 analysts).
  • Affected industries: Manufacturing, Technology, Healthcare, Government, Consulting, Managed Security Service Providers (MSSPs).
  • Attack channels: website.
  • Impersonated: SharePoint / OneDrive / DocuSign (trusted business service) and Microsoft device login.

Awareness takeaways

  • Train employees that ‘legitimate’ Microsoft login pages can still be part of a scam if they are being asked to approve or enter a code they didn’t initiate.
  • Add specific guidance for SharePoint/OneDrive/DocuSign-themed lures: don’t sign in from unexpected document prompts; navigate to the service directly via a known bookmark.
  • Coach staff to treat unexpected ‘device code’ requests as a high-risk sign-in and report them immediately to reduce the chance of token-based access persisting.

Red flags to watch for

  • You are asked to enter a code you did not request into a login flow
  • A ‘trusted’ document brand page redirects you into a device-code authentication step
  • The sign-in looks legitimate because it uses Microsoft’s real page, reducing obvious phishing signals
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you help an attacker log in to Microsoft 365… on Microsoft’s real website. Kali365 does this with a fake SharePoint or DocuSign page that says, “View document,” then sends you to Microsoft’s device login and tells you to enter a code they provide. Here’s the catch: you’re on a real Microsoft page, but it’s not your sign-in. When you enter their code and approve, you hand over access tokens to your email, OneDrive, and SharePoint. If a SharePoint, OneDrive, or DocuSign link ever tells you to enter a device code you didn’t start, stop, close it, and report it to security right away.

Similar attacks

Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
QR-PDF Phishing Hits M365, MFA Bypass Surges

QR-PDF Phishing Hits M365, MFA Bypass Surges

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies,…

July 28, 2026
Greatness PhaaS Adds Device-Code MFA Bypass

Greatness PhaaS Adds Device-Code MFA Bypass

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026