Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A new criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Key points
- Kali365 is a phishing kit sold to criminals that targets US companies by abusing Microsoft's real login page.
- Victims are tricked into approving a device code, a short string Microsoft uses to log in devices without keyboards, that the attacker controls.
- Once approved, the criminals receive access and refresh tokens, digital keys that keep them logged in even after passwords change.
- Compromised accounts expose corporate email, documents in OneDrive and SharePoint, and other cloud resources.
- The attack sidesteps many multi-factor authentication setups because the victim personally clicks approve on a genuine Microsoft screen.
A phishing kit called Kali365 is being used to break into US company accounts by weaponising Microsoft's own sign-in page against the staff who use it every day.
The technique was flagged in reporting from The Hacker News and is aimed squarely at organisations that run on Microsoft 365, the cloud version of Outlook, Word and Teams that most offices now depend on.
What is Kali365 actually doing?
It is abusing a normal Microsoft feature called device code login. That feature exists so you can sign a smart TV or printer into your work account by typing a short code on microsoft.com from your phone.
The criminals generate one of these codes on their own machine. They then send a phishing email, a fake message pretending to be from IT or a colleague, asking the target to "verify" or "activate" something by entering the code on the real Microsoft page.
The victim sees a genuine microsoft.com address, a genuine login prompt, and their own familiar company branding. They approve the code. Behind the scenes, they have just signed the attacker's device into their account.
Why is this harder to stop than normal phishing?
Because nothing on the victim's screen looks fake. There is no dodgy website to spot and no password to hand over.
Most phishing training tells staff to check the web address in the browser bar. Here the address is correct. The login page is the real one. Even multi-factor authentication, the second step where you approve a prompt on your phone, is satisfied, because the victim is the one approving it.
Once Microsoft issues the tokens, the attacker holds two things: an access token that opens the account now, and a refresh token that quietly gets new access tokens later. Changing the password does not always kick them out.
What can the attackers do with the account?
Everything the employee could do. That means reading email, downloading files from OneDrive and SharePoint, browsing Teams chats, and pulling contact lists to attack more people inside the same company.
From there the usual crimes follow: invoice fraud, where a fake payment instruction is sent from a real internal address; theft of commercial documents; and setting up quiet forwarding rules so the criminals see replies before the real user does.
| Attack element | What it means in plain English |
|---|---|
| Kali365 | A ready-made phishing kit sold to other criminals |
| Device code abuse | Tricking a user to approve the attacker's login on the real Microsoft page |
| Access token | A digital key that logs the attacker in right now |
| Refresh token | A key that keeps issuing new access tokens over time |
What should ordinary staff watch for?
Any message asking you to enter a short code on a Microsoft page to "activate", "verify" or "join" something you did not start yourself. If you did not initiate the login on your own device, do not enter the code. Ring your IT team on a known number and ask.
If you have already approved one, tell IT immediately. They can revoke the tokens and force every session to sign out, which is the only clean way to lock the attacker back out.



