Ethical Hacking News
Kali365: A Sophisticated Phishing Kit Abuses Microsoft Authentication to Target US Organizations
Kali365 is a sophisticated phishing kit that weaponizes Microsoft authentication protocols to target US-based organizations. The campaign has bypassed numerous businesses' defenses, compromising sensitive data and IT infrastructure. Kali365 exploits trust in legitimate business services like SharePoint, OneDrive, and DocuSign to trick victims into entering attacker-provided code. The attackers rotate domains, URLs, and hosting infrastructure to evade detection. The campaign is highly organized and well-funded, posing a significant threat to US-based organizations. Kali365 manipulates legitimate Microsoft authentication protocols, creating a direct path to data exposure and financial fraud. Security leaders face a critical challenge in addressing Kali365, requiring current campaign intelligence and better preparation for evolving threats. ANYRUN has developed strategies to help organizations mitigate the impact of Kali365, including leveraging Threat Intelligence Feeds and Interactive Sandbox.
The threat landscape has recently been dealt a significant blow courtesy of Kali365, a phishing kit that weaponizes legitimate Microsoft authentication protocols to target organizations based in the United States. According to recent reports, this sophisticated campaign has managed to bypass the defenses of numerous businesses, compromising their sensitive data and placing their entire IT infrastructure at risk.
At its core, Kali365 is a device code phishing kit designed to exploit the trust that users have in legitimate business services such as SharePoint, OneDrive, and DocuSign. By impersonating these trusted entities, the attackers are able to trick victims into entering an attacker-provided code on Microsoft's real authentication page. Once this process is initiated, the attackers are granted access and refresh tokens, which they can use to gain continued access to Microsoft 365 email, documents, and cloud resources.
This campaign appears to be particularly well-orchestrated, with attackers rotating domains, URLs, and hosting infrastructure as part of their ongoing efforts to evade detection. However, thanks to the efforts of security researchers at ANY.RUN, more information is now available about this sophisticated phishing kit.
According to ANY.RUN's Threat Intelligence Feeds, Kali365 has been linked to over 80 public sessions each week, with the United States serving as its primary geographic target. This level of sophistication and scale suggests that the attackers involved in this campaign are highly organized and well-funded, which makes them a formidable foe for any organization that falls victim to their tactics.
One notable aspect of Kali365 is its ability to manipulate legitimate Microsoft authentication protocols, which can be notoriously difficult to defend against. By doing so, the attackers are able to create a direct path to data exposure, financial fraud, operational disruption, and costly incident response – all of which have serious consequences for any organization that is compromised.
The potential impact of Kali365 cannot be overstated. For US-based organizations, the consequences may include financial fraud, sensitive data exposure, operational disruption, higher response costs, compliance and reputational risk, and even more severe consequences such as business email compromise.
In light of this campaign, security leaders are facing a critical challenge in addressing Kali365. Simply relying on email filtering alone is no longer sufficient, as the attackers involved in this campaign are able to rotate domains, URLs, and hosting infrastructure at will. Instead, security leaders need current campaign intelligence, faster validation of suspicious activity, and better preparation for how the threat may evolve.
To address this challenge, ANY.RUN has developed several strategies that can help organizations mitigate the impact of Kali365. These include expanding detection with actionable phishing intelligence, providing Tier 1 teams with the evidence they need to act on Kali365, and turning threat research into proactive defense.
For instance, organizations can expand their detection capabilities by leveraging ANYRUN's Threat Intelligence Feeds, which deliver newly observed indicators through STIX/TAXII, API, and SDK. By doing so, security teams can enrich alert decision-making, conduct retrospective searches, and block malicious activity more effectively.
Similarly, Tier 1 teams can benefit from ANYRUN's Interactive Sandbox, which combines hands-on interaction with automated analysis to reveal the full attack chain faster – from phishing pages and redirect paths to network activity and the transition into Microsoft's authentication flow. This tool provides AI summaries, recommendations, and all the evidence needed for faster handoff.
Finally, organizations can turn threat research into proactive defense by utilizing ANYRUN's Threat Intelligence Lookup and Threat Intelligence Reports. These tools provide context on related infrastructure, relevant sandbox sessions, lure screenshots, and targeting patterns – giving defenders a clearer view of where the campaign is active and which domains, URLs, and infrastructure may be connected to it.
In conclusion, Kali365 represents a significant threat to organizations based in the United States, particularly those that rely heavily on Microsoft 365 for their email, documents, and cloud resources. By exploiting legitimate Microsoft authentication protocols, this phishing kit has managed to bypass defenses and compromise sensitive data – highlighting the need for ongoing vigilance and proactive defense measures.
To mitigate the impact of Kali365, security leaders must prioritize current campaign intelligence, faster validation of suspicious activity, and better preparation for evolving threats. By leveraging ANYRUN's Threat Intelligence Feeds, Interactive Sandbox, and Threat Intelligence Lookup tools, organizations can enhance their defenses and reduce the risk associated with this sophisticated phishing kit.
Related Information:
https://www.ethicalhackingnews.com/articles/Kali365-A-Sophisticated-Phishing-Kit-Abuses-Microsoft-Authentication-to-Target-US-Organizations-ehn.shtml
https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html
Published: Wed Aug 5 07:41:30 2026 by llama3.2 3B Q4_K_M