Kali365 and Device Code Phishing: What Businesses Need to Know

by Bill Dickherber

The FBI recently issued an alert about a new phishing platform called Kali365, a tool that is making it easier for cybercriminals to gain access to Microsoft 365 accounts and business data.

What makes this threat different is that attackers may not need to steal passwords at all. Instead, they trick users into granting access to their accounts through a process that appears legitimate, allowing attackers to bypass traditional security measures and maintain access to company resources.

For businesses that rely on Microsoft 365 for email, file sharing, and collaboration, this serves as an important reminder that cyber threats continue to evolve, and employee awareness remains one of the strongest defenses.


What Is Kali365?

According to the FBI, Kali365 is a Phishing-as-a-Service (PhaaS) platform that first appeared in April 2026. Like many “as-a-service” offerings, it provides cybercriminals with ready-made tools that make launching phishing attacks easier and more accessible.

The platform reportedly includes:

  • AI-generated phishing messages
  • Automated phishing campaign templates
  • Real-time tracking dashboards
  • Tools designed to capture Microsoft 365 access tokens

Because these tools require less technical expertise to operate, more attackers can launch sophisticated phishing campaigns than ever before.


How the Attack Works

Unlike traditional phishing attacks that focus on stealing usernames and passwords, Kali365 abuses a legitimate Microsoft authentication feature known as device code authentication.

Device code authentication is designed for devices and applications that cannot easily display a traditional login screen, such as streaming devices, point-of-sale (POS) systems, and certain developer tools. Instead, the user is provided with a short code and directed to a Microsoft sign-in page where they can complete the authentication process using another device.

Cybercriminals exploit this process through a technique known as device code phishing.


How Device Code Phishing Works

Device code phishing is a social engineering attack that tricks users into authorizing an attacker’s device to access their account. Rather than stealing passwords, attackers abuse a legitimate authentication process and convince users to unknowingly approve access on their behalf.

he graphic shown above, along with portions of the information in this blog, is based on two Microsoft security research articles: “Storm-2372 Conducts Device Code Phishing Campaign (February 2025) and Inside an AI-Enabled Device Code Phishing Campaign (April 2026). Together, they provide a clear illustration of how device code phishing attacks work.

As shown in the graphic, the attacker initiates a legitimate login request for a service such as Microsoft 365. They then send a phishing email that impersonates a trusted service, often a cloud productivity, collaboration, or document-sharing platform. The email contains a device code and instructions directing the recipient to visit a legitimate Microsoft verification page, such as microsoft.com/devicelogin, and enter the code.

Because both the email and the authentication process appear legitimate, many users do not realize they are being targeted. The Microsoft sign-in page is real, but the device code was generated by the attacker and is tied to the attacker’s authentication request. When the victim enters the code and approves the request, they unknowingly authorize the attacker’s device to access their account. Microsoft then issues OAuth access and refresh tokens to the attacker’s session.

This is an example of what the “authorization” screen would look like, and where the victim would put the code.

With those tokens, the attacker can gain access to Microsoft 365 services such as Outlook, Teams, and OneDrive without needing the victim’s password. The attacker may also be able to maintain access for as long as the tokens remain valid, potentially allowing them to access sensitive information, send additional phishing emails, and move laterally within the organization.

Microsoft has discovered another example of Device code phishing, through a fake Microsoft Teams Invitation.

Example of a Fake Microsoft Teams Invitation

  1. You receive a phishing email or Teams message (sometimes from spoofed legitimate accounts) requesting you to join a meeting.
  2. When you go to enter the meeting, the shown below will pop up asking you to enter the meeting ID code.
  3. The code is not a meeting ID; it is a real device authorization code initiated by the attacker. When you enter it, you are effectively telling Microsoft, “This is my device, authorize it,” giving the attacker full access to your Microsoft 365, Outlook, and Teams.


Why This Matters for Businesses

Many organizations have invested heavily in stronger passwords and multi-factor authentication (MFA), and those protections remain important. However, the FBI’s warning highlights a growing trend in cybercrime: attackers are finding ways to exploit user trust rather than technical vulnerabilities.

A successful attack could potentially lead to:

  • Unauthorized access to business email accounts
  • Exposure of sensitive company data
  • Access to shared files and documents
  • Business disruption and financial loss
  • Reputational damage with customers and partners

For organizations of any size, even a single compromised account can create significant risk.

What Businesses Can Do

The FBI recommends reviewing Microsoft device code authentication settings and limiting or blocking device code flows when possible. Organizations should also audit existing usage before making changes to ensure business operations are not affected.

In addition to technical controls, businesses should focus on employee education and awareness. Team members should be trained to recognize unusual login requests, unexpected verification prompts, and phishing emails that create urgency or request immediate action.

Cybersecurity is no longer just an IT issue. It is a business-wide responsibility that requires a combination of technology, policies, and informed employees.


What to Do If You Suspect Your Account Has Been Compromised

The FBI encourages individuals and organizations impacted by the Kali365 phishing kit to report the incident to the Internet Crime Complaint Center (IC3).

According to the FBI, reports should include as much information as possible, including:

  • Copies of any phishing emails, including email headers and message content
  • Details about suspicious login activity, such as timestamps, IP addresses, and locations
  • Information about any unauthorized devices or active sessions connected to the account

Reporting these incidents helps law enforcement track emerging cyber threats and may assist in ongoing investigations.

You can file a report with the Internet Crime Complaint Center (IC3) at www.ic3.gov.


The Bottom Line

The FBI’s Alert and the man articles Microsoft has released about device code phishing are great reminders that phishing attacks continue to evolve, and they will continue to happen on a daily basis. While attackers once focused primarily on stealing passwords, today’s threats increasingly rely on manipulating users into granting access themselves.

Businesses that combine strong security controls with ongoing employee education will be in a better position to reduce risk and respond effectively to emerging threats.

Sources:

FBI Kali365 Alert
Microsoft: Storm-2372 Conducts device code Phishing
Microsoft: Inside an AI‑enabled device code phishing campaign


Stay Ahead of Emerging Cyber Threats

The FBI’s warning about Kali365 and the Microsoft warnings about Device Code Phishing, highlights an important reality: cybercriminals are constantly adapting their tactics. Businesses that invest in security awareness, strong access controls, and proactive cybersecurity planning are better positioned to defend against these evolving threats.

At OCCSI, we help organizations strengthen their cybersecurity posture through employee training, managed security services, compliance support, and strategic IT guidance.

If you’d like to discuss ways to better protect your business, employees, and data, call 636-332-1335. Our team is ready to help you build a stronger, more resilient security strategy.

Contact us today

Picture of Bill Dickherber
Bill Dickherber

Bill Dickherber is the CEO of Onsite Computer Consulting, a leading provider of managed IT support and cloud solutions. With over 15+ years of experience in the IT industry, Bill brings a deep understanding of the evolving technology landscape and a proven track record of helping businesses stay secure, scalable, and ahead of the curve.

Throughout his career, Bill has built and led high-performing teams, developed strategic partnerships, and guided organizations through complex digital transformations. Under his leadership, Onsite Computer Consulting has grown into a trusted IT partner for businesses across industries — delivering proactive support, cutting-edge cloud security, and tailored IT infrastructure solutions that drive real business value.

Bill is passionate about empowering businesses through technology, streamlining operations, and fostering long-term client relationships built on trust, responsiveness, and results.

Get a Free Consultation

Contact our experts today

Recent Posts: