A new phishing-as-a-service platform dubbed Kali365 is abusing Microsoft’s legitimate device code authentication flow to hijack Microsoft 365 sessions at scale, bypassing multi-factor authentication and granting attackers long-lived access to corporate email and cloud data.[1][2][4]
According to a public service announcement from the FBI, Kali365 emerged in April 2026 and is being sold via criminal channels as a turnkey service that lets low-skill operators obtain Microsoft 365 access and refresh tokens without ever capturing a victim’s username or password.[1][6] Security researchers describe the kit as an industrialized ecosystem: customers pay a subscription fee, receive polished phishing templates that mimic business tools like SharePoint and DocuSign, and then manage stolen sessions through a web dashboard.[2][6][11]
The attack hinges on Microsoft’s OAuth device code flow, which is designed to let users sign in on a trusted page by entering a short alphanumeric code rather than clicking a link in an email.[1][2][10] Kali365 operators initiate a legitimate device code request for their own malicious cloud application, then trick targets into entering that code on Microsoft’s real login page, where the victim completes a genuine sign-in and MFA challenge.[1][2][4] Because the attacker’s application started the flow and is polling for completion, it silently receives OAuth access and refresh tokens as soon as the user authenticates, effectively granting the threat actor full access to Outlook, OneDrive, Teams and other Microsoft 365 services without any further prompts.[1][3][10]
Once in possession of valid tokens, criminals can read and manipulate email, access internal documents, monitor chats and potentially abuse trusted identities for business email compromise, data theft and internal phishing, all while appearing to be a fully authenticated user.[1][2][7] Several analyses note that refresh tokens obtained via Kali365 can remain valid even after a victim resets their password, allowing attackers to maintain persistence unless tokens are explicitly revoked or session lifetimes are tightly constrained.[9][10] Reporting around the campaigns indicates that US companies across sectors are being targeted, with lures tailored to finance, legal and operations staff who routinely receive document-sharing requests.[1][4][5]
Importantly, there is currently no CVE associated with Kali365’s core technique; security assessments emphasize that the kit exploits a legitimate identity feature rather than a software flaw, mapping instead to weaknesses such as improper authentication and session management.[10][13] An engineering review cited in incident response guidance explicitly concludes that no product vulnerability applies, underscoring that traditional patching alone will not mitigate this class of attacks.[13] Microsoft has previously warned that similar device code phishing campaigns, including activity attributed to the threat group it tracks as Storm-2372, rely on the same basic pattern of tricking users into authorizing attacker-controlled sessions via standard OAuth flows.[14][15]
Defenders are being urged to treat device code phishing as an identity configuration and monitoring problem, not just an email filtering issue.[10][14][15] Recommended countermeasures include disabling or severely limiting the device code flow where possible, enforcing conditional access policies that restrict which applications can use it, and requiring stronger controls such as security keys for high-risk accounts.[10][14][15] Organizations should also monitor sign-in logs and OAuth consent activity for unusual device code authorizations or unfamiliar applications, and rapidly revoke refresh tokens and sign-in sessions when compromise is suspected.[8][10][15] User education remains critical as well: staff should be trained to treat unsolicited instructions to enter a device code with the same skepticism as any login link, and to verify such requests through trusted channels before proceeding.[5][7][8]
References
- Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 …
- Kali365: The New Phishing Kit Hijacking Microsoft 365 …
- FBI warns of Kali365 phishing kit that breaks into Microsoft …
- Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
- Protect Against Kali365 Device-Code Phishing & Token Theft
- Kali365: when the session becomes the new credential
- Kali365 Phishing Attack Bypasses Microsoft 365 MFA Using Real …
- How should home and small org users address Kali365 …
- Kali365 Unmasked: How a Phishing Kit Defeated MFA …
- How to Detect Kali365 Phishing Attack With M365 Manager …
- Inside Kali365, a Device Code Phishing Ecosystem
- SCC-CAM-2026-0363
- Inside an AI‑enabled device code phishing campaign
- Storm-2372 conducts device code phishing campaign
