A sophisticated phishing kit, identified as Kali365, is actively targeting organizations in the United States by exploiting Microsoft’s authentication system. This tactic, known as device code phishing, manipulates legitimate processes to gain unauthorized access to Microsoft 365 accounts.
How the Kali365 Phishing Method Operates
Unlike traditional phishing schemes that redirect victims to fake login pages, Kali365 directs users to Microsoft’s authentic Device Login page. Here, users are tricked into entering a device code provided by attackers, which facilitates the authorization of an attacker-controlled application or session.
This method enables cybercriminals to acquire OAuth access and refresh tokens, allowing them to maintain access to corporate emails, SharePoint files, OneDrive, and other cloud services without needing to directly steal passwords.
Mechanics of Device Code Phishing
Kali365 exploits the device authorization flow, a feature meant for devices with limited input options, such as smart TVs and IoT devices. Attackers send a phishing message, often camouflaged as a SharePoint or document-sharing request, prompting recipients to visit the Microsoft device login portal with a specified code.
Once victims enter the code on the legitimate Microsoft site, attackers gain OAuth tokens, providing temporary resource access. Even if victims change their passwords later, authorized tokens could still be valid until manually revoked.
Implications for Organizations
ANY.RUN’s telemetry reveals that Kali365 predominantly targets sectors like manufacturing, technology, government, healthcare, and consulting. Approximately 80 public sandbox sessions link to this phishing kit weekly, indicating widespread activity.
The phishing campaign is not limited to one industry; instead, it aims at organizations heavily reliant on Microsoft 365. Compromised accounts can lead to severe consequences, including business email compromise, data theft, and internal spear-phishing.
Preventive Measures and Analysis
Organizations must train employees to avoid entering unsolicited device codes from emails or messages. Security teams should monitor for unusual device code authentication events and implement controls like Conditional Access policies and multi-factor authentication (MFA).
By analyzing ANY.RUN’s sandbox sessions, analysts can better understand the infrastructure and indicators of compromise associated with Kali365. Rapid token revocation and application consent controls are critical in minimizing exposure to such attacks.
Understanding and addressing these threats is crucial for reducing the risk of significant financial and operational impacts from such phishing activities.
