Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Key points
- Kali365 is a phishing kit sold to criminals that targets US companies by abusing Microsoft's real login page.
- Victims are tricked into approving a device code, a short string Microsoft uses to log in devices without keyboards, that the attacker controls.
- Once approved, the criminals receive access and refresh tokens, digital keys that keep them logged in even after passwords change.
- Compromised accounts expose corporate email and cloud files in OneDrive and SharePoint.
- The attack sidesteps many multi-factor authentication setups because the victim personally clicks approve on a genuine Microsoft screen.
A phishing kit called Kali365 is being used to break into US company accounts by weaponising Microsoft's own sign-in page against the staff who use it every day. Device code phishing has spread fast this year: our 31 July story found identity teams already struggling to contain it before Kali365 made the toolkit available to lower-skilled criminals.
What is Kali365 actually doing?
It abuses a normal Microsoft feature called device code login, the one that lets you sign a smart TV or printer into your work account by typing a short code on microsoft.com from your phone.
The criminals generate one of these codes on their own machine, then send a phishing email pretending to be from IT or a colleague and asking the target to "verify" or "activate" something. The victim sees a genuine microsoft.com address and their own familiar company branding. They approve the code. Behind the scenes, they've just signed the attacker's device into their account.
Why is this harder to stop than normal phishing?
Nothing on the victim's screen looks fake. No dodgy website to spot, no password to hand over.
Most phishing training tells staff to check the web address in the browser bar. Here the address is correct. The login page is the real one. Even multi-factor authentication, the second step where you approve a prompt on your phone, is satisfied, because the victim is the one approving it. This same bypass appeared in Forg365, the $400-a-month kit we reported on 13 July, and again in Greatness on 4 August. Kali365 is the third such kit we've reported since July.
Once Microsoft issues the tokens, the attacker holds two things: an access token that opens the account immediately, and a refresh token that quietly generates new access tokens later. Changing the password doesn't always kick them out.
What can the attackers do with the account?
Everything the employee could do. That means reading email, downloading files, and pulling contact lists to attack more people inside the same company.
From there the usual crimes follow: invoice fraud, where a fake payment instruction is sent from a real internal address; theft of commercial documents; and quiet forwarding rules so the criminals see replies before the real user does.
| Attack element | What it means in plain English |
|---|---|
| Kali365 | A ready-made phishing kit sold to other criminals |
| Device code abuse | Tricking a user to approve the attacker's login on the real Microsoft page |
| Access token | A digital key that logs the attacker in right now |
| Refresh token | A key that keeps issuing new access tokens over time |
What should ordinary staff watch for?
Any message asking you to enter a short code on a Microsoft page to "activate", "verify" or "join" something you didn't start yourself. Don't enter the code. Ring your IT team on a known number and ask.
If you've already approved one, tell IT immediately. They can revoke the tokens and force every session to sign out, which is the only clean way to lock the attacker back out. What matters most here isn't the sophistication of the kit; it's that approving one prompt is all it takes, and no amount of password hygiene undoes it.



