Actor Profile

Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on Microsoft's real login portal. The operation shows sustained activity with over 80 public sandbox sessions recorded weekly, primarily focused on US-based enterprises across manufacturing, technology, healthcare, government, consulting, and MSSP sectors. The campaign's motivation appears to be financial gain and data theft through persistent Microsoft 365 access. Operators demonstrate capability to rotate domains, URLs, and hosting infrastructure as campaigns evolve.

TTPs (Tactics, Techniques, Procedures)

The campaign employs a three-stage attack chain: (1) Initial access via phishing lures impersonating trusted business services (SharePoint, OneDrive, DocuSign); (2) Credential access through legitimate Microsoft device login portal abuse, where victims are instructed to enter attacker-provided device codes; (3) Persistence via OAuth token theft, obtaining access and refresh tokens that provide continued access to Microsoft 365 email, documents, and cloud resources. The abuse of legitimate Microsoft authentication infrastructure allows malicious activity to blend with routine authentication events, delaying detection. Post-compromise activities include email account compromise for business email compromise (BEC) and invoice manipulation, data exfiltration of corporate email and internal files, and unauthorized access to cloud services.

Targets & Patterns

Kali365 primarily targets US-based organizations across multiple enterprise sectors including manufacturing, technology, healthcare, government, consulting, and managed security service providers (MSSPs). The campaign focuses on organizations using Microsoft 365 environments, exploiting the widespread trust in Microsoft authentication pages. The geographic concentration on United States targets suggests either language/cultural familiarity requirements for social engineering effectiveness or specific interest in US corporate data and financial systems. The cross-sector targeting pattern indicates opportunistic victim selection rather than vertical-specific espionage, consistent with financially-motivated cybercrime operations seeking access to email systems for BEC fraud, payment redirection, and sensitive data theft.

Historical Context

The article presents Kali365 as an active campaign with sustained weekly activity (80+ public sandbox sessions per week) as of August 2026. The campaign represents an evolution in OAuth abuse tactics, specifically weaponizing Microsoft's device code authentication flow—a legitimate feature designed for devices with limited input capabilities. This technique builds on broader trends in phishing campaigns moving away from credential harvesting toward token theft and authentication abuse that bypasses traditional password-based defenses and multi-factor authentication. The campaign's ability to rotate infrastructure and maintain persistent operations suggests an established phishing-as-a-service or organized cybercrime operation rather than an isolated incident.

Defensive Recommendations

  • Implement conditional access policies in Microsoft 365 to restrict device code authentication flows to approved devices and locations, blocking unauthorized device registration attempts
  • Monitor Azure AD sign-in logs for device code flow authentications (especially from unfamiliar locations or devices) and establish alerting for unusual OAuth token issuance patterns
  • Deploy email security controls and user awareness training specifically addressing device code phishing tactics, emphasizing verification of unexpected authentication requests even on legitimate Microsoft pages
  • Establish threat intelligence integration to ingest fresh Kali365 IOCs (domains, URLs, infrastructure) into SIEM, SOAR, TIP, and firewall systems for blocking and retrospective hunting
  • Conduct proactive threat hunting for Kali365 indicators across Microsoft 365 environments, reviewing recent device registrations and OAuth consent grants for suspicious patterns, and implement token lifetime policies to limit persistence window of compromised refresh tokens

---

# Geopolitical Context

Geopolitical Context

The Kali365 campaign represents a sophisticated exploitation of trusted authentication infrastructure to compromise US corporate environments. By weaponizing Microsoft's legitimate device code authentication flow, the operation demonstrates an evolution in phishing tradecraft that bypasses traditional email security controls. The campaign's focus on US organizations across manufacturing, technology, healthcare, government, and consulting sectors suggests either a financially motivated cybercriminal operation seeking high-value targets or a more strategic effort to establish persistent access within American enterprise networks. The geographic concentration and sector diversity indicate systematic targeting rather than opportunistic activity. The abuse of OAuth flows and legitimate cloud authentication mechanisms reflects broader trends in adversary adaptation to cloud-first enterprise architectures, where traditional perimeter defenses offer limited protection against identity-based attacks.

State Actor Alignment

No state actor attribution is provided in the available reporting. The campaign appears consistent with financially motivated cybercrime operations, particularly given the emphasis on business email compromise, invoice manipulation, and payment fraud as primary consequences. However, the systematic targeting of US government entities alongside private sector organizations, combined with the focus on persistent access to email, documents, and cloud resources, leaves open the possibility of intelligence collection objectives. The technical sophistication of weaponizing legitimate Microsoft authentication infrastructure and the operational discipline reflected in sustained weekly activity (80+ public sandbox sessions) suggest a well-resourced threat actor. Without additional attribution indicators, the operation should be treated as a credible threat to US enterprise security regardless of ultimate sponsorship. The lack of clear state nexus does not diminish the strategic risk, as persistent access to corporate Microsoft 365 environments can support both financial fraud and longer-term espionage objectives.

Business Impacty pro region

The campaign's concentration on United States targets has direct implications for transatlantic business operations and allied information security. US companies with European subsidiaries or partners may serve as vectors for lateral compromise across jurisdictions, particularly where shared Microsoft 365 tenants or federated authentication systems are employed. The targeting of consulting firms and managed security service providers (MSSPs) presents a supply chain risk, as compromised service providers could enable access to multiple client environments across North America and Europe. For NATO allies and Five Eyes partners, the compromise of US government entities through this vector raises concerns about potential exposure of shared intelligence or defense-related communications conducted via commercial cloud platforms. The healthcare sector targeting is particularly significant given the sensitivity of patient data and the regulatory frameworks governing transatlantic health information exchange under GDPR and HIPAA. European organizations conducting business with targeted US sectors should anticipate similar phishing attempts adapted to their regional authentication infrastructure, as successful techniques are typically replicated across allied markets by both cybercriminal and state-sponsored actors.

Forecast

If Kali365 operators maintain current operational tempo and the campaign continues to evade traditional email filtering, the volume of compromised Microsoft 365 accounts is likely to increase across targeted US sectors over the coming weeks. Should the technique prove consistently effective, similar device code phishing kits are likely to emerge from other threat actors, expanding the risk beyond the current campaign. If compromised accounts are leveraged for business email compromise or invoice fraud, financial losses may prompt increased regulatory scrutiny of cloud authentication security practices, potentially accelerating adoption of phishing-resistant multifactor authentication requirements. Should any compromised government or defense contractor accounts be identified, the incident may trigger interagency coordination through CISA and result in targeted advisories to cleared defense industrial base entities. If the campaign expands geographically beyond the United States, European organizations are likely to be the next primary target given similar reliance on Microsoft 365 infrastructure and comparable business processes. The persistence of access tokens means that even if initial compromise is detected, full remediation may require enterprise-wide token revocation and authentication policy changes, likely causing operational disruption for affected organizations.