A newly uncovered phishing-as-a-service (PhaaS) platform dubbed Kali365 is making waves in the cybercrime underground by exploiting a lesser-known Microsoft 365 feature to bypass multi-factor authentication (MFA) and infiltrate US enterprises. The campaign, detailed by cybersecurity researchers at rescana.com, marks a significant escalation in the sophistication of credential-harvesting operations, as it leverages the legitimate Device Code Flow protocol to trick users into granting access to attackers.
Unlike traditional phishing kits that rely on fake login pages, Kali365 abuses a standard Microsoft authentication mechanism designed for devices without browsers. This approach not only evades MFA protections but also makes detection considerably harder for security teams, raising urgent concerns for organizations heavily reliant on Microsoft 365 services.
Understanding Kali365 and the Device Code Flow Attack
Kali365 operates as a subscription-based service, offering cybercriminals an easy-to-deploy toolkit for launching highly effective phishing campaigns. Its core innovation lies in the exploitation of Device Code Flow, a feature intended to authenticate users on devices like smart TVs, command-line interfaces, and IoT hardware. In this flow, the user receives a code to enter on a separate device, which is exactly where Kali365 strikes.
Attackers initiate a legitimate Microsoft 365 authentication request and then trick victims into entering the provided device code on a genuine Microsoft login page. Because the request originates from Microsoft's own infrastructure, the system trusts it, and even if MFA is enabled, the attacker can complete the login by having the victim approve the request unknowingly. This effectively renders MFA useless, as the victim believes they are simply authorizing their own session.
Why This Bypass Is Particularly Dangerous
- Legitimate infrastructure abuse: The attack uses real Microsoft domains, making it nearly impossible for email filters and URL scanners to flag it as malicious.
- MFA fatigue minimized: Instead of bombarding users with push notifications, Kali365 presents a single, seemingly harmless code entry request.
- Low technical barrier: The PhaaS model means even novice criminals can execute sophisticated attacks without deep coding knowledge.
- Wide enterprise impact: Microsoft 365 is the backbone of countless US companies, making the potential attack surface enormous.
How the Attack Unfolds in Real-World Scenarios
According to the rescue report, Kali365 campaigns typically begin with a highly convincing spear-phishing email. The message often impersonates a trusted colleague, IT administrator, or vendor, urging the recipient to verify their account or approve a security update. The email contains a link that directs the victim to a page mimicking a Microsoft 365 sign-in prompt, but with a twist: instead of asking for a password directly, it instructs the user to generate and enter a device code.
Once the victim follows the steps, the attacker's backend receives the code and immediately initiates a real authentication request on their end. The victim is then prompted to approve the login on their own device, which they do, believing it is a routine security check. This single approval grants the attacker a valid session token, complete with any MFA claims, effectively handing over control of the user's mailbox, files, and connected services.
Post-Compromise Activities Observed
Rescana's analysis revealed that after gaining access, Kali365 operators engage in a range of malicious activities, including:
- Email forwarding rules to monitor and intercept sensitive communications.
- Credential harvesting from emails and cloud-stored documents.
- Lateral movement within the corporate network to reach high-value systems.
- Data exfiltration of proprietary business information for ransomware or extortion.
How Enterprises Can Defend Against Kali365 and Similar Threats
The emergence of Kali365 underscores the need for a multi-layered security posture that goes beyond traditional MFA. While MFA remains a critical control, organizations must assume that attackers can bypass it and implement additional safeguards to detect and respond to anomalous authentication patterns.
Security teams should closely monitor for unusual device code authentication requests, especially those originating from unexpected geographic locations or non-standard device types. Enforcing conditional access policies that restrict device code flow to legitimate scenarios can significantly reduce the attack surface.
Practical Mitigation Steps
- Disable Device Code Flow unless absolutely necessary for business operations.
- Implement risk-based conditional access to challenge or block suspicious sign-ins.
- Educate users about the risks of entering codes from unsolicited emails, even on legitimate-looking pages.
- Deploy advanced threat detection tools that can spot session anomalies and post-compromise behaviors.
- Conduct regular phishing simulations that include device code attack scenarios.
Key Takeaways
Kali365 represents a stark reminder that cybercriminals continuously evolve their tactics to exploit trusted technologies. The abuse of Microsoft 365's Device Code Flow to bypass MFA is a sophisticated method that can deceive even security-aware users. US enterprises must act now to review their authentication policies, disable unnecessary features, and enhance monitoring to stay ahead of this emerging threat.
As PhaaS platforms become more advanced and accessible, the barrier to launching damaging attacks continues to lower. Organizations should view this as a call to action to adopt zero-trust principles and ensure that no single authentication method is trusted implicitly. The time to harden defenses is before the next phishing kit comes knocking.
Zyra