Start with Identity
← Blog
News

Kali365 phishes Microsoft's own device login page for durable Microsoft 365 tokens

ANY.RUN documented Kali365, a kit that lures victims through fake SharePoint, OneDrive, and DocuSign pages to Microsoft's genuine device login portal, where approving an attacker-supplied code hands over access and refresh tokens.

By SWI Community TeamAug 5, 2026Updated Aug 29, 2026

ANY.RUN researchers detailed Kali365 on August 5, 2026, a phishing kit that turns Microsoft's legitimate device login portal into the attack surface. Victims hit a lure impersonating SharePoint, OneDrive, or DocuSign, get redirected to the genuine Microsoft device login page, and enter an attacker-supplied code. Approving it issues the attacker access and refresh tokens with continued reach into Microsoft 365 mail, documents, and cloud resources. Because every page the victim actually sees is real Microsoft infrastructure, the usual phishing tells are absent. ANY.RUN telemetry shows more than 80 public sessions a week. Targets skew to US manufacturing, technology, healthcare, government, consulting, and managed security providers.

Why it matters

Kali365 is the commodity version of the technique three state-linked crews adopted the same month. That is the pattern worth tracking: device-code flow abuse has moved from espionage tradecraft to a kit anyone can rent. Traditional user training fails here because there is nothing fake to spot on the login page, and domain-based blocklists fail because the domain is login.microsoftonline.com. The controls that work are policy-level. Disable device-code flow for tenants that do not need it, use Conditional Access to require a compliant device for token issuance, and alert specifically on device-code grants. Follow-on damage is invoice fraud and mailbox access, so pair this with the token theft response checklist.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.