Kali365 Phishing-as-a-Service Exploits Microsoft 365 Device Code Flow to Bypass MFA and Compromise US Enterprises

Kali365 Phishing-as-a-Service Exploits Microsoft 365 Device Code Flow to Bypass MFA and Compromise US Enterprises

Executive Summary

The emergence of the Kali365 Phishing-as-a-Service (PhaaS) platform marks a significant escalation in the threat landscape for US enterprises leveraging Microsoft 365. Kali365 weaponizes the legitimate Microsoft device code authentication flow, enabling adversaries to bypass multi-factor authentication (MFA) and gain persistent, unauthorized access to enterprise cloud environments without requiring password theft. This campaign, which has been the subject of urgent advisories from the FBI, leading security vendors, and threat intelligence platforms, presents a new class of enterprise risk that is both highly effective and difficult to detect. The attack leverages trusted Microsoft infrastructure, making traditional detection and prevention mechanisms less effective and increasing the urgency for organizations to adopt advanced mitigation strategies.

Threat Actor Profile

Kali365 is not attributed to a single advanced persistent threat (APT) group but is instead a commercialized PhaaS platform distributed via Telegram and underground forums. The service is available by subscription, with pricing reported at approximately $250 per month or $2,000 per year. The platform is designed for ease of use, offering AI-generated phishing lures, automated campaign orchestration, real-time dashboards, and robust OAuth token capture capabilities. The democratization of this attack vector means that a wide range of cybercriminals, from low-skilled actors to organized crime groups, can launch sophisticated campaigns against US enterprises. There is currently no evidence of nation-state sponsorship, but the scale and automation of Kali365 campaigns have enabled widespread exploitation across multiple sectors.

Technical Analysis of Malware/TTPs

The core innovation of Kali365 lies in its abuse of the Microsoft OAuth 2.0 device code flow, a legitimate authentication mechanism intended for devices with limited input capabilities (such as smart TVs or IoT devices). The attack chain unfolds as follows: Victims receive highly convincing phishing emails impersonating trusted business services such as SharePoint, OneDrive, or DocuSign. These emails contain a device code and instructions to visit the official Microsoft device login portal (e.g., https://microsoft.com/devicelogin). When the victim enters the attacker-supplied code, Microsoft’s infrastructure issues OAuth access and refresh tokens—directly to the attacker—granting persistent access to the victim’s Microsoft 365 account, including Outlook, Teams, OneDrive, and other integrated services.

This method is particularly insidious because it does not require the attacker to harvest credentials or bypass MFA directly. Instead, the victim unwittingly authorizes the attacker’s device, and the resulting OAuth tokens can be used to maintain access until explicitly revoked. The Kali365 kit automates the entire process, from lure generation to token harvesting and session management. The platform also rotates infrastructure and phishing domains frequently, complicating detection and takedown efforts.

MITRE ATT&CK mapping for this campaign includes: - T1566.002: Spearphishing via Service (phishing emails with device code) - T1078.004: Valid Accounts: Cloud Accounts (use of legitimate OAuth tokens) - T1550.003: Use Alternate Authentication Material: OAuth Tokens - T1192: Spearphishing Link (phishing email with link to Microsoft login)

Exploitation in the Wild

Telemetry from ANY.RUN and other threat intelligence platforms indicates that Kali365 is responsible for over 80 public attack sessions per week, with the United States as the primary target. The FBI issued a public service announcement in May 2026, warning of the campaign’s ability to bypass MFA and compromise Microsoft 365 environments without password theft. Security researchers at Bitdefender and other vendors have confirmed hundreds of successful intrusions, with attackers leveraging persistent OAuth tokens to access sensitive data, manipulate business processes, and facilitate financial fraud.

The attack is highly scalable, with documented incidents across manufacturing, technology, healthcare, government, consulting, and managed security service providers (MSSPs). The phishing lures are tailored to the target organization, increasing the likelihood of user interaction and successful compromise. The infrastructure supporting Kali365 is highly dynamic, with frequent domain and URL rotation to evade blacklists and automated defenses.

Victimology and Targeting

The primary victims of Kali365 campaigns are US-based enterprises, particularly those operating in sectors with high-value data and critical business processes. Manufacturing, technology, healthcare, government, consulting, and MSSPs have all been disproportionately targeted. The attack methodology is sector-agnostic, but the phishing lures are often customized to mimic the workflows and branding of the victim organization’s most-used cloud services. While the United States remains the epicenter of activity, there is evidence of spillover into North America and Europe, with organizations in these regions also reporting incidents.

The attack does not discriminate by organization size; both large enterprises and mid-sized businesses have been affected. The common denominator is reliance on Microsoft 365 and the presence of users with the ability to authorize device code flows. The campaign’s success is amplified by the fact that it leverages legitimate Microsoft infrastructure, making it difficult for users and security teams to distinguish malicious activity from normal authentication events.

Mitigation and Countermeasures

To defend against Kali365 and similar device code flow abuse, organizations must adopt a multi-layered approach that combines technical controls, user education, and continuous monitoring. The most effective mitigation is to block the device code flow for all users except those with a documented business need. This can be achieved by creating a conditional access policy in Microsoft Entra ID (formerly Azure AD) that restricts device code authentication. Before enforcement, organizations should audit existing device code flow usage to identify legitimate dependencies and exclude emergency access accounts to prevent lockouts.

Continuous monitoring of Microsoft 365 sign-in logs is essential to detect suspicious device authorizations, particularly those following device code authentication events. Security teams should update their SIEM and SOAR platforms with the latest indicators of compromise (IOCs) from threat intelligence feeds such as ANY.RUN and STIX/TAXII. User awareness training should emphasize the risks of unsolicited requests to enter codes on Microsoft’s device login page, even when the page appears legitimate.

For organizations seeking to further harden their authentication posture, the deployment of phishing-resistant MFA solutions—such as hardware security keys using FIDO2/WebAuthn—is strongly recommended. These technologies are inherently resistant to token theft via device code flow and provide an additional layer of defense against sophisticated phishing campaigns.

References

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their extended enterprise ecosystem. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify emerging threats, streamline risk assessments, and enhance overall cyber resilience. For more information about our solutions or to request a threat intelligence briefing, please contact us at info@rescana.com.