Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk The Hacker News Aug 05, 2026 Phishing / Identity Security Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud, operational disruption, and costly incident response. How Kali365 Targets US Organizations Kali365 is a device code phishing kit built to abuse legitimate Microsoft authentication. ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week, with the United States emerging as its main geographic target. One of these sandbox sessions shows a SharePoint-themed lure used to draw the victim into the authentication flow. View the analysis session and gather IOCs SharePoint-themed Kali365 lure analyzed inside ANY.RUN’s Interactive Sandbox Based on the research, the attack unfolds in three main stages: Lure: The victim is presented with a page impersonating a trusted business service such as SharePoint, OneDrive, or DocuSign. Microsoft authentication: The page redirects the victim to Microsoft's legitimate device login portal and asks them to enter an attacker-provided code. OAuth access: Once the victim completes authentication, attackers may obtain access and refresh tokens that provide continued access to Microsoft 365 email, documents, and cloud resources. Reveal the full phishing chain in as little as 60 seconds to reduce response delays and prevent a single compromised account from becoming a wider business incident. Reduce Incident Risk What Kali365 Can Cost the Business A single approved device-code request can expand into a wider Microsoft 365 compromise. For US companies, the consequences may include: Financial fraud: Compromised email accounts can support invoice manipulation, payment fraud, and business email compromise. Sensitive data exposure: Attackers may access corporate email, internal files, customer information, and confidential documents. Operational disruption: Unauthorized access to cloud services can interfere with daily communications and business processes. Higher response costs: Fewer obvious phishing indicators can delay detection and make containment more complex. Compliance and reputational risk: Exposure of regulated or customer data can trigger reporting obligations and damage trust. As the victim authenticates on Microsoft's legitimate page, the activity may appear routine at first, giving attackers more time to misuse trusted access before the incident is confirmed. Three Priorities for Reducing Kali365 Risk Kali365 cannot be addressed through email filtering alone. Security leaders need current campaign intelligence, faster validation of suspicious activity, and better preparation for how the threat may evolve. 1. Expand Detection with Actionable Phishing Intelligence Kali365 operators can rotate domains, URLs, and hosting infrastructure as campaigns evolve. Indicators from one confirmed case may quickly become outdated, leaving gaps across the rest of the environment. Fresh phishing IOCs should reach SIEM, SOAR, TIP, firewalls, and other security controls where they can support alert enrichment, retrospective searches, and blocking decisions. ANY.RUN's Threat Intelligence Feeds deliver newly observed indicators through STIX/TAXII, API, and SDK. Get fresh and trustworthy IOCs on emerging threats for deeper investigations The intelligence is drawn from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals worldwide. Each IOC links back to the session where it appeared, giving defenders the full context needed to verify the threat and identify related Kali365 infrastructure. 2. Give Tier 1 the Evidence Needed to Act on Kali365 As victims authenticate on Microsoft's legitimate device login page, Kali365 may look like normal activity at first. The real warning signs often appear earlier, in the lure, redirects, browser behavior, scripts, and attacker-controlled infrastructure. ANY.RUN's Interactive Sandbox combines hands-on interaction with automated analysis to reveal the full attack chain faster, from the phishing page and redirect paths to network activity and the transition into Microsoft's authentication flow. Tier 1 reports include AI summaries, recommendations and all the evidence needed for faster handoff Auto-generated reports bring together the verdict, IOCs, TTPs, and behavioral evidence in a shareable format. This helps Tier 1 confirm malicious activity sooner, hand off complex cases with clearer context, and support faster containment before access spreads across Microsoft 365. 3. Turn Threat Research into Proactive Defense Kali365 activity can be explored beyond a single alert by checking current campaign data in ANY.RUN's Threat Intelligence Lookup. The results provide context on related infrastructure, relevant sandbox sessions, lure screenshots, and targeting patterns. For US-focused activity, teams can run the following query: threatName:"kali365" AND submissionCountry:"US" Kali365 activity targeting US organizations uncovered in ANY.RUN’s Threat Intelligence Lookup The results show Kali365 activity across manufacturing, technology, healthcare, government, consulting, and MSSPs . This gives defenders a clearer view of where the campaign is active and which domains, URLs, and infrastructure may be connected to it. Threat Intelligence Reports add a broader layer of preparation. These reports are manually compiled by ANY.RUN analysts and focus on active malware and phishing campaigns, including APTs and cybercriminal groups. TI reports created by ANY.RUN analysts for deeper investigations Each report includes investigation findings and TI Lookup queries that teams can apply to threat hunting, detection reviews, and incident enrichment. This helps SOC teams track emerging attack patterns earlier and prepare before similar activity reaches their environment. Shut Down Token Abuse Before It Reaches the Business Kali365 puts pressure on a part of the security stack many organizations still treat as trusted by default: cloud authentication. The CISO challenge is to ensure the SOC can recognize when a legitimate login flow has been manipulated, trace the activity back to its source, and contain access before email, files, or business systems are affected. Organizations using ANY.RUN have reported: 94% faster threat triage , helping critical incidents move to action before they are delayed by alert backlogs. Up to 21 minutes less MTTR per case , reducing the window in which attackers can expand access or misuse trusted accounts. Up to 20% lower Tier 1 workload , creating more investigation capacity without immediately adding headcount. 30% fewer Tier 1-to-Tier 2 escalations , allowing senior analysts to focus on complex incidents and higher-risk decisions. These gains lower response costs, improve the use of existing SOC resources, and shorten the window for token abuse to escalate into fraud, data exposure, or operational disruption. Contain identity-based threats with behavioral evidence before they reach critical business systems. Cut MTTR by 21 Mins Per Case Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE Cloud security , data security , enterprise security , Identity Security , Incident response , Microsoft , OAuth Security , Phishing , Security Operations , Threat Intelligence ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders