Kali365 kit steals Microsoft OAuth tokens
TechnologyBreaking
Archived — This article has been archived. The information may be outdated.

Kali365 kit steals Microsoft OAuth tokens

Cybersecurity News··23 Jul

The Kali365 phishing kit abuses Microsoft device code authentication, redirecting victims to genuine Microsoft login pages while stealing OAuth tokens, researchers reported. ANY.RUN sandbox telemetry recorded more than 80 sessions per week, largely targeting US users. The kit lets attackers maintain access without capturing passwords directly. Kali365 abuses Microsoft device code authentication flows. Victims are redirected to genuine Microsoft.

Prism

What It Means For You

  • Kali365 redirects victims to real Microsoft login pages while stealing OAuth tokens.
  • The phishing kit abuses Microsoft device code flows popular in enterprise sign-ins.
  • ANY.RUN recorded more than 80 sandbox sessions per week targeting US users.

What's Happening

  • Researchers flagged the Kali365 phishing kit abusing Microsoft device codes.
  • It redirects users to authentic Microsoft login screens to harvest OAuth tokens.
  • Security sandbox ANY.RUN logged 80 plus weekly sessions, mainly US targets.

Device Codes As Phishing Bait

  • Device code authentication simplifies remote logins but can be hijacked by lookalike flows.
  • OAuth token theft lets attackers persist without storing passwords.
  • Enterprises relying on Microsoft identity should review device code policies.
all-newstop-stories

More in Technology