CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Kali365 Phishing Kit Exploits Microsoft Device Code Flow to Target US Enterprises

August 5, 2026

Kali365, a device code phishing kit, is actively targeting US organizations by abusing Microsoft’s legitimate authentication flow. According to ANY.RUN telemetry, the campaign records more than 80 public sandbox sessions weekly, with the United States as the primary target. The attack begins with a lure page impersonating trusted services like SharePoint, OneDrive, or DocuSign, then redirects victims to Microsoft’s legitimate device login portal where they enter an attacker-provided code. Once the victim authenticates, attackers obtain OAuth access and refresh tokens, granting continued access to Microsoft 365 email, documents, and cloud resources.

The consequences for compromised organizations include financial fraud through invoice manipulation and business email compromise, sensitive data exposure, operational disruption, higher incident response costs, and compliance and reputational risks. Because the authentication occurs on Microsoft’s real page, the activity may appear routine, delaying detection and enabling attackers to misuse trusted access.

To mitigate Kali365 risk, security leaders should expand detection with actionable phishing intelligence, ensuring fresh IOCs reach SIEM, SOAR, TIP, and firewalls. ANY.RUN’s Threat Intelligence Feeds deliver indicators via STIX/TAXII, API, and SDK, drawn from over 15,000 organizations and 600,000 security professionals. Tier 1 analysts can use ANY.RUN’s Interactive Sandbox to reveal the full attack chain, with AI summaries and recommendations for faster handoff. Proactive defense involves using Threat Intelligence Lookup to query campaign data, such as threatName:”kali365″ AND submissionCountry:”US”, to identify related infrastructure and targeting patterns. ANY.RUN’s Threat Intelligence Reports, manually compiled by analysts, provide deeper investigation findings and queries for threat hunting.

Organizations using ANY.RUN report 94% faster threat triage, up to 21 minutes less MTTR per case, 20% lower Tier 1 workload, and 30% fewer escalations, reducing response costs and shortening the window for token abuse to escalate into fraud or data exposure.

CVEs: CVE-2026-50522

Malware: Kali365

Companies: ANY.RUN

Products: ANY.RUN Interactive Sandbox, ANY.RUN Threat Intelligence Feeds, ANY.RUN Threat Intelligence Lookup, ANY.RUN Threat Intelligence Reports