threat_intelligence1127 wordsRead on Arc Codex

Kali365 and why stealing passwords is no longer enough

Kali365 and why stealing passwords is no longer enough How phishing kits are turning legitimate Microsoft sign-ins into attack opportunities Key takeaways - The Kali365 phishing kit epitomizes a major shift in phishing, from stealing passwords to abusing legitimate authentication processes. - Victims may complete a genuine Microsoft sign-in and MFA process, yet still grant attackers access to cloud accounts, sessions or tokens. - Defending against these attacks requires visibility across email, identity, authentication, and post-login activity rather than credential protection alone. Attacks abusing authentication processes are on the rise. Since early 2026, Kali365, a phishing-as-a-service (PhaaS) platform targeting Microsoft 365 environments, has abused authentication processes in waves of attacks. A number of cybersecurity vendors and the FBI have reported on Kali365, and Barracuda researchers have seen many Kali365 attacks in recent months. This article details Barracuda’s findings. From credential theft to authentication abuse Traditional phishing attacks are often detected by security tools that identify suspicious websites, fake sign-in pages, credential-harvesting forms, or known malicious domains. Phishing kits such as Kali365 take a different approach. Instead of stealing passwords directly, attackers abuse legitimate Microsoft authentication mechanisms, using device code authentication and adversary-in-the-middle (AiTM) session hijacking. The victim may authenticate through a genuine Microsoft login experience and still unknowingly grant access to an attacker-controlled session. As a result, many of the warning signs that users and security tools have relied on for years have become less effective. Turning everyday business processes into authentication traps What makes Kali365 — and other, similar platforms — particularly effective is the ability to disguise authentication attacks as routine business activities. The Kali365 attack campaigns seen by Barracuda researchers feature protected or encrypted messages, links to shared documents, electronic signature requests, payment and invoice notifications, voicemail alerts, mailbox storage warnings, quarantine review requests, and compliance and security notifications. None of these are new or innovative. In each case, the victim believes they are performing a normal business task. The request appears relevant to their role and consistent with everyday workflows. Rather than being asked to provide credentials, they are instructed to complete what appears to be a legitimate verification step. A sample phishing email with a link to a malicious landing page One of Kali365’s primary techniques is device code phishing, an increasingly popular approach that Barracuda Research has reported on previously. How device code phishing works The attack begins when a victim receives a phishing email containing a link to a malicious landing page. Instead of presenting a fake Microsoft login form, the page displays a device verification code and instructs the user to continue authentication through Microsoft’s legitimate device login process. The victim is guided to an authentic Microsoft page and completes the sign-in and multifactor authentication (MFA) process as normal. A sample authentication message Because authentication occurs on Microsoft’s legitimate login infrastructure, users encounter a genuine sign-in experience rather than a fake credential-harvesting page. The attacker instead abuses the resulting authenticated session or tokens. Why traditional phishing indicators become less reliable The success of device code phishing highlights the weakness of traditional phishing defenses, which were designed to detect attempts to steal credentials. In many cases, MFA bypass techniques are no longer necessary because the attacker is not trying to circumvent multifactor authentication. Instead, they persuade the user to complete a legitimate authentication workflow on the attacker’s behalf. For security teams, the authentication logs may initially appear legitimate, and traditional website reputation checks don’t raise any red flags. Beyond passwords: targeting tokens and sessions Kali365 also supports adversary-in-the-middle (AiTM) attacks that enable session hijacking and token theft. In these attacks, a malicious proxy sits between the victim and the Microsoft authentication service. The victim again completes a genuine login and MFA, while the attacker captures the resulting authentication session or tokens and reuses them to access the account. A sample attack email for an AiTM attack Once access to the authenticated Microsoft 365 session is obtained, attackers can reach email and files, search for financial information, monitor communications, create mailbox rules, configure email forwarding, conduct business email compromise attacks, and move laterally through cloud services. For technical researchers — the code to look for When the victim clicks the link in the phishing email, the page secretly sends a request to the attacker’s server to create a new Microsoft device login session. The attacker’s server then contacts Microsoft’s Device Code Authentication service and receives: - user_code: the short code the victim must enter (e.g. ABCD-EFGH) - device_code: a hidden identifier Microsoft uses internally - verification_url: where the victim should go to authenticate, usually Microsoft’s real device login page The phishing page shows the victim the code they need to copy and enter. This looks harmless because people are used to entering short verification codes when connecting apps and devices. The phishing page opens Microsoft’s real login page (the verification URL). In practice, this is often microsoft.com/devicelogin or another genuine Microsoft device authentication page. The victim is now looking at a real Microsoft login page, not a fake one. The victim enters the user code (e.g. ABCD-EFGH) then signs in and completes MFA, thereby authenticating the attacker’s device. Meanwhile the phishing page keeps contacting the attacker’s server. Until the moment Microsoft responds with: “status = success”. This means that Microsoft has issued the authentication tokens linked to the device code request. The attacker can then use those tokens to access Microsoft 365 resources, and the victim is redirected elsewhere. A sample device code phishing email What organizations should watch for Because these attacks rely on legitimate authentication workflows, organizations need visibility beyond email security alone. Key warning signs may include: - Unexpected device code authentication activity. - Users being asked to enter device verification codes. - OAuth grants to unfamiliar applications. - Unusual Microsoft 365 sign-in patterns. - New device registrations following authentication events. - Suspicious mailbox rule creation. - Unexpected email forwarding activity. - Abnormal access to SharePoint, OneDrive, Teams, or Exchange resources. The strongest detections often come from correlating signals across email, web, identity, and post-authentication activity rather than relying on a single indicator. Conclusion Kali365 reflects a broader evolution in phishing. Rather than stealing credentials through fake login pages, attackers increasingly exploit trusted authentication workflows and routine business processes to gain authenticated access. As a result, organizations must look beyond password theft and focus on protecting identities, authentication workflows, sessions, OAuth permissions, and post-login activity across cloud environments. 2026 Email Threats Report Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected Subscribe to the Barracuda Blog. Sign up to receive threat spotlights, industry commentary, and more. The Managed XDR Global Threat Report Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.