Kali365 is a device code phishing kit that targets US organizations by abusing legitimate Microsoft authentication pages to obtain OAuth access and refresh tokens. It uses multi-brand lure templates and multiple backend endpoints to blend in with normal login activity while exposing Microsoft 365, SharePoint, and other cloud resources to account takeover. #Kali365 #Microsoft365 #SharePoint #DocuSign #OneDrive
Keypoints
- Kali365 targets US organizations and Microsoft 365 users, with more than 80 public ANY.RUN sessions observed each week.
- The phishkit uses device code phishing, directing victims to a legitimate Microsoft device login page instead of a fake login form.
- Successful authentication allows attackers to obtain OAuth access and refresh tokens, enabling continued access without stealing the victim’s password.
- ANY.RUN observed strong targeting across multiple industries, including MSSPs, manufacturing, technology, government, healthcare, and consulting.
- Kali365 uses many lure templates to impersonate trusted brands and services such as SharePoint, OneDrive, Teams, DocuSign, and Google Drive.
- The campaign commonly uses .de domains and supports both Microsoft and Google device authorization flows, though Microsoft is used most often.
- Recommended defenses include revoking active sessions and refresh tokens, reviewing OAuth permissions, and monitoring for unusual device-code and token activity.
MITRE Techniques
- [T1078 ] Valid Accounts – Attackers abuse legitimate Microsoft authentication to gain access through normal sign-in flows (‘the victim authenticate through a legitimate Microsoft page’ and ‘obtain OAuth access and refresh tokens’).
- [T1550.001 ] Use Alternate Authentication Material: Application Access Token – The attack relies on OAuth access and refresh tokens to maintain access without repeatedly stealing passwords (‘obtain the OAuth access and refresh tokens’ and ‘continued access … without stealing the victim’s password directly’).
- [T1189 ] Drive-by Compromise – Victims are redirected from a lure page to a real Microsoft login page as part of the phishing flow (‘directed to Microsoft’s legitimate device login page’).
- [T1566.002 ] Phishing: Spearphishing Link – The lure page and redirect flow are used to trick users into initiating the device-code authentication process (‘SharePoint-themed lure’ and ‘persuaded to enter it on the authentic Microsoft Device Login page’).
- [T1204.001 ] User Execution: Malicious Link – The victim must interact with the lure and enter the attacker-provided code to complete the flow (‘After interacting with the lure, the victim is directed to Microsoft’s legitimate device login page’).
- [T1090 ] Proxy – The attackers mediate access through legitimate Microsoft and Google device-code flows while hiding the true origin of the phishing infrastructure (‘supports both Microsoft and Google device authorization flows’).
Indicators of Compromise
- [Domains] Related phishing infrastructure and lure domains – bluefoodtruths[.]xyz, flexiscalesystems[.]de, guardextion[.]online, and 2 more domains
- [Domains] Additional related phishing domains used in the campaign – cloud-microsoft-drive-for-business[.]workers[.]dev, txatvrk[.]net, hbaknoxvillecom[.]top, and 2 more domains
- [URLs] Device-code and lure backend endpoints used by Kali365 – /api/generate?lure=
, /api/lure-config/ - [URLs] Polling endpoints used to check device-code session status – /api/status/
, /api/google/status/ - [URLs] Legitimate authentication and device authorization pages abused in the flow – login.microsoftonline.com/common/oauth2/deviceauth, google.com/device
- [File/Template Names] Kali365 lure and configuration labels observed in the code – onedrive, sharepoint, ms_teams_meeting, and other template names
Read more: https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/