Kali365 Targets US Organizations with Data Theft via Device Code Phishing 

Kali365 Targets US Organizations with Data Theft via Device Code Phishing 
Kali365 is a device code phishing kit that targets US organizations by abusing legitimate Microsoft authentication pages to obtain OAuth access and refresh tokens. It uses multi-brand lure templates and multiple backend endpoints to blend in with normal login activity while exposing Microsoft 365, SharePoint, and other cloud resources to account takeover. #Kali365 #Microsoft365 #SharePoint #DocuSign #OneDrive

Keypoints

  • Kali365 targets US organizations and Microsoft 365 users, with more than 80 public ANY.RUN sessions observed each week.
  • The phishkit uses device code phishing, directing victims to a legitimate Microsoft device login page instead of a fake login form.
  • Successful authentication allows attackers to obtain OAuth access and refresh tokens, enabling continued access without stealing the victim’s password.
  • ANY.RUN observed strong targeting across multiple industries, including MSSPs, manufacturing, technology, government, healthcare, and consulting.
  • Kali365 uses many lure templates to impersonate trusted brands and services such as SharePoint, OneDrive, Teams, DocuSign, and Google Drive.
  • The campaign commonly uses .de domains and supports both Microsoft and Google device authorization flows, though Microsoft is used most often.
  • Recommended defenses include revoking active sessions and refresh tokens, reviewing OAuth permissions, and monitoring for unusual device-code and token activity.

MITRE Techniques

  • [T1078 ] Valid Accounts – Attackers abuse legitimate Microsoft authentication to gain access through normal sign-in flows (‘the victim authenticate through a legitimate Microsoft page’ and ‘obtain OAuth access and refresh tokens’).
  • [T1550.001 ] Use Alternate Authentication Material: Application Access Token – The attack relies on OAuth access and refresh tokens to maintain access without repeatedly stealing passwords (‘obtain the OAuth access and refresh tokens’ and ‘continued access … without stealing the victim’s password directly’).
  • [T1189 ] Drive-by Compromise – Victims are redirected from a lure page to a real Microsoft login page as part of the phishing flow (‘directed to Microsoft’s legitimate device login page’).
  • [T1566.002 ] Phishing: Spearphishing Link – The lure page and redirect flow are used to trick users into initiating the device-code authentication process (‘SharePoint-themed lure’ and ‘persuaded to enter it on the authentic Microsoft Device Login page’).
  • [T1204.001 ] User Execution: Malicious Link – The victim must interact with the lure and enter the attacker-provided code to complete the flow (‘After interacting with the lure, the victim is directed to Microsoft’s legitimate device login page’).
  • [T1090 ] Proxy – The attackers mediate access through legitimate Microsoft and Google device-code flows while hiding the true origin of the phishing infrastructure (‘supports both Microsoft and Google device authorization flows’).

Indicators of Compromise

  • [Domains] Related phishing infrastructure and lure domains – bluefoodtruths[.]xyz, flexiscalesystems[.]de, guardextion[.]online, and 2 more domains
  • [Domains] Additional related phishing domains used in the campaign – cloud-microsoft-drive-for-business[.]workers[.]dev, txatvrk[.]net, hbaknoxvillecom[.]top, and 2 more domains
  • [URLs] Device-code and lure backend endpoints used by Kali365 – /api/generate?lure=, /api/lure-config/
  • [URLs] Polling endpoints used to check device-code session status – /api/status/, /api/google/status/
  • [URLs] Legitimate authentication and device authorization pages abused in the flow – login.microsoftonline.com/common/oauth2/deviceauth, google.com/device
  • [File/Template Names] Kali365 lure and configuration labels observed in the code – onedrive, sharepoint, ms_teams_meeting, and other template names


Read more: https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/