Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
Kali365, a Phishing-as-a-Service (PaaS) platform, is targeting US companies with device code phishing that abuses Microsoft’s legitimate authentication process. The attack comes just a few months after the FBI warned that Kali365 was targeting Microsoft 365 accounts.
By obtaining OAuth (Open Authorization) access and refresh tokens, attackers may gain continued access to corporate email, documents, and cloud services without directly stealing a password. For businesses, a single successful authorization can lead to data exposure, financial fraud, operational disruption, and higher incident response costs.
US Companies Are Kali365’s Primary Target
ANY.RUN telemetry shows that the United States is the main geographic target of Kali365. More than 80 public sessions linked to the phishing kit appear in the ANY.RUN database each week, indicating sustained activity against US companies.
Security teams can explore this...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE