Kali365 Phishing Kit Exploits Microsoft Device Code Flow to Target US Enterprises
Kali365, a device code phishing kit, is actively targeting US organizations by abusing Microsoft's legitimate authentication flow. According to ANY.RUN telemetry, the…
Kali365, a device code phishing kit, is actively targeting US organizations by abusing Microsoft's legitimate authentication flow. According to ANY.RUN telemetry, the…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
Tycoon2FA is a well-known AiTM phishing kit that added device code phishing support in May 2026. It was previously tracked as the…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Forg365 is a phishing-as-a-service (PhaaS) operation that uses device code phishing, AitM tactics, and AI-assisted lures to compromise Microsoft 365 accounts. It…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
Storm-2372 is a nation-state threat actor that was among the first to use device code phishing in the wild, starting in 2024.…
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…