Kali365 Abuses Microsoft Device Login Flows to Target US Organizations

Kali365 is using Microsoft’s legitimate device login process to target US organizations, turning attacker-controlled codes into potential access to Microsoft 365 email, documents, and cloud resources. ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week, with the United States emerging as its primary geographic target.
The phishing kit starts with a page impersonating a familiar business service such as SharePoint, OneDrive, or DocuSign. A victim is then redirected to Microsoft’s authentic device login portal and instructed to enter a code supplied by the attacker.
How legitimate authentication becomes the attack path
If the victim completes authentication, the attacker may obtain access and refresh tokens. Those tokens can provide continued access to Microsoft 365 resources, even though the user entered credentials on a genuine Microsoft page rather than a conventional fake login form.
This reliance on trusted infrastructure can make the activity appear routine at first. The more revealing signs may occur before authentication, including the lure, redirects, browser behavior, scripts, and attacker-controlled infrastructure.
The campaign extends the Kali365 MFA bypass and supply-chain attack pattern by showing how manipulated cloud authentication can create persistent access to trusted business systems.
Business exposure from one approved request
A single approved device-code request can develop into a broader Microsoft 365 compromise. Access to corporate mailboxes may enable invoice manipulation, payment fraud, and business email compromise. Email, internal files, customer information, and confidential documents may also be exposed.
Unauthorized cloud access can disrupt communications and daily processes. Because obvious phishing indicators may be limited, detection can take longer, containment may become more complex, and exposure of regulated or customer data can create reporting and reputational consequences.
Detection and response priorities
Email filtering alone does not address Kali365. ANY.RUN says operators can rotate domains, URLs, and hosting infrastructure, so indicators from one case may quickly lose value. Fresh phishing indicators should reach SIEM, SOAR, threat intelligence platforms, firewalls, and other controls for enrichment, retrospective searches, and blocking decisions.
ANY.RUN’s Threat Intelligence Feeds distribute indicators through STIX/TAXII, API, and SDK. The intelligence is drawn from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals, with each indicator linked to the session in which it appeared.
Its Interactive Sandbox combines hands-on interaction with automated analysis to expose phishing pages, redirect paths, network activity, and the transition into Microsoft authentication. Generated reports consolidate verdicts, indicators, TTPs, and behavioral evidence for analyst handoff and containment.
Security teams can also search Threat Intelligence Lookup with threatName:"kali365" AND submissionCountry:"US". The observed US activity spans manufacturing, technology, healthcare, government, consulting, and managed security service providers.
Practical implication for security leaders
Organizations need to treat cloud authentication as an attack surface rather than trusted activity by default. SOC teams should be able to connect a legitimate device login to its originating lure and redirects, identify related infrastructure, and revoke abused access before email, files, or business systems are affected.
ANY.RUN reports that customers achieved 94% faster threat triage, reduced mean time to respond by up to 21 minutes per case, lowered Tier 1 workload by up to 20%, and cut Tier 1-to-Tier 2 escalations by 30%. The business objective is to shorten the interval between suspicious authentication and containment, limiting the opportunity for token abuse to become fraud, data exposure, or operational disruption.

