Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Kali365 Exploits Microsoft Codes to Breach Accounts

Kali365 Exploits Microsoft Codes to Breach Accounts

Posted on July 23, 2026 By CWS

A sophisticated phishing kit, identified as Kali365, is actively targeting organizations in the United States by exploiting Microsoft’s authentication system. This tactic, known as device code phishing, manipulates legitimate processes to gain unauthorized access to Microsoft 365 accounts.

How the Kali365 Phishing Method Operates

Unlike traditional phishing schemes that redirect victims to fake login pages, Kali365 directs users to Microsoft’s authentic Device Login page. Here, users are tricked into entering a device code provided by attackers, which facilitates the authorization of an attacker-controlled application or session.

This method enables cybercriminals to acquire OAuth access and refresh tokens, allowing them to maintain access to corporate emails, SharePoint files, OneDrive, and other cloud services without needing to directly steal passwords.

Mechanics of Device Code Phishing

Kali365 exploits the device authorization flow, a feature meant for devices with limited input options, such as smart TVs and IoT devices. Attackers send a phishing message, often camouflaged as a SharePoint or document-sharing request, prompting recipients to visit the Microsoft device login portal with a specified code.

Once victims enter the code on the legitimate Microsoft site, attackers gain OAuth tokens, providing temporary resource access. Even if victims change their passwords later, authorized tokens could still be valid until manually revoked.

Implications for Organizations

ANY.RUN’s telemetry reveals that Kali365 predominantly targets sectors like manufacturing, technology, government, healthcare, and consulting. Approximately 80 public sandbox sessions link to this phishing kit weekly, indicating widespread activity.

The phishing campaign is not limited to one industry; instead, it aims at organizations heavily reliant on Microsoft 365. Compromised accounts can lead to severe consequences, including business email compromise, data theft, and internal spear-phishing.

Preventive Measures and Analysis

Organizations must train employees to avoid entering unsolicited device codes from emails or messages. Security teams should monitor for unusual device code authentication events and implement controls like Conditional Access policies and multi-factor authentication (MFA).

By analyzing ANY.RUN’s sandbox sessions, analysts can better understand the infrastructure and indicators of compromise associated with Kali365. Rapid token revocation and application consent controls are critical in minimizing exposure to such attacks.

Understanding and addressing these threats is crucial for reducing the risk of significant financial and operational impacts from such phishing activities.

Cyber Security News Tags:ANY.RUN, cloud security, cyber attacks, Cybersecurity, device code phishing, email compromise, identity theft, Kali365, MFA, Microsoft 365, OAuth tokens, Phishing, security threats, token management

Post navigation

Previous Post: Hackers Exploit MFA to Hijack Microsoft 365 Sessions
Next Post: AI-Coded Applications: Security Challenges Uncovered

Related Posts

BlankGrabber Stealer Conceals Malware with Fake Certificates BlankGrabber Stealer Conceals Malware with Fake Certificates Cyber Security News
Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes Cyber Security News
Thousands of Fortinet Firewalls Targeted in Global Cyber Attack Thousands of Fortinet Firewalls Targeted in Global Cyber Attack Cyber Security News
Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks Cyber Security News
LLM Agent Powers Cyberattack on Internal Database LLM Agent Powers Cyberattack on Internal Database Cyber Security News
Starkiller Phishing Tool Bypasses MFA with Real Login Pages Starkiller Phishing Tool Bypasses MFA with Real Login Pages Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark