A phishing email that never asks for your password. A login page you visit yourself. An authentication flow you complete with your own multifactor approval. The account takeover happens anyway, because the attacker simply borrowed the session you authorized. This is device code phishing, and Kali365 has turned it into a service anyone can rent.

Kali365 Device code phishing

The phishing-as-a-service platform known as Kali365 has rapidly evolved from a specialized tool focused on compromising Microsoft 365 accounts into a much broader account takeover ecosystem targeting both enterprise and consumer services worldwide. What began as a narrow Microsoft-focused utility now functions as a full identity-compromise operation spanning multiple cloud providers, messaging platforms, and authentication systems.

Initially recognized for its ability to bypass multifactor authentication (MFA) through device code phishing attacks against Microsoft 365 users, Kali365 has expanded its capabilities significantly. Recent research from Arctic Wolf indicates that the platform now targets a diverse range of cloud services and identity providers, including Amazon Web Services (AWS), Okta, Xerox DocuShare, and several major Russian online platforms.

Among the most notable additions is MAX Messenger, a Russian state-backed messaging application that has reportedly accumulated more than 80 million users and is being promoted as a national communications platform. Security researchers believe this expansion reflects a deliberate effort by the operators to maximize access to large user populations while pursuing both enterprise and consumer targets at the same time.

Understanding Device Code Phishing

The success of Kali365 stems from its abuse of a legitimate authentication mechanism known as device code authorization. This method was originally designed to simplify login for devices that lack full web browsers or keyboards, such as smart televisions, streaming devices, conference room systems, printers, and various Internet-of-Things platforms.

Under normal circumstances, a device displays a short authorization code and instructs the user to visit a legitimate login page on another trusted device. After entering the code and successfully authenticating, the service links the user’s account to the original device. It is a convenient, well-intentioned workflow, and that is exactly what makes it dangerous when abused.

Kali365 exploits this workflow rather than attempting to steal usernames and passwords directly. The attack begins when a threat actor generates a legitimate OAuth 2.0 device authorization request. Victims are then tricked into entering the provided code through carefully crafted phishing emails or messages that impersonate trusted services such as Microsoft OneDrive, SharePoint, cloud collaboration platforms, or security verification requests. Once the victim authenticates and completes any required MFA challenge, the cloud service issues valid access tokens to the attacker’s session.

From the service provider’s perspective, the authentication is entirely legitimate. The user voluntarily completed every required verification step, so the attacker gains access without ever obtaining the password.
Why traditional MFA offers little defense against device code phishing

Traditional MFA protections offer little defense in this scenario because the victim unknowingly performs the authentication process on behalf of the attacker. The security control works exactly as designed; it simply protects the wrong session.

Lowering the Barrier for Cybercriminals

One of the most concerning aspects of Kali365 is its accessibility. The platform has transformed a technically complex attack technique into a service that can be operated by relatively inexperienced threat actors. According to public reporting, it bundles together everything an operator needs to run a campaign:

What the Kali365 platform provides to its operators
1
AI-generated phishing content. Convincing lure emails and messages produced automatically, reducing the language and design skill an attacker would otherwise need.
2
Automated campaign templates. Prebuilt impersonation kits for trusted brands and identity providers, ready to deploy at scale.
3
Victim tracking dashboards. Real-time visibility into who has received, opened, and acted on a phishing message.
4
Token capture functionality. Automatic collection of the valid access tokens issued once a victim completes authentication.
5
Centralized management interfaces. A single console to run, monitor, and scale multiple campaigns at once.

These capabilities significantly reduce the technical expertise required to conduct sophisticated account compromise operations and allow attackers to launch campaigns at scale. This trend reflects a broader evolution within the cybercrime ecosystem, where advanced attack techniques are increasingly packaged into subscription-based services that can be purchased and operated much like legitimate software-as-a-service platforms.

From Microsoft 365 Theft to a Multi-Platform Operation

MITRE ATT@CK for Kali365

Recent investigations indicate that Kali365 has expanded well beyond its original Microsoft-focused scope. Researchers identified a cluster of more than 100 active malicious hosts operating the phishing infrastructure during a single observation period. These systems were found impersonating numerous trusted brands and authentication providers.

Brands and providers impersonated by Kali365 infrastructure
Microsoft Outlook & Live
The platform’s original focus, still actively impersonated to capture Microsoft 365 access tokens.
Okta Single Sign-On
A major enterprise identity provider, targeted to compromise federated access across many connected applications.
Amazon Web Services
Cloud infrastructure accounts whose compromise can expose extensive enterprise resources and data.
Xerox DocuShare
An enterprise content and document management platform, broadening the platform’s business-application reach.
Mail.ru & Yandex Disk
Major Russian email and cloud-storage services, extending targeting to large consumer populations.
Odnoklassniki & MAX Messenger
Popular Russian social and messaging platforms, including a state-backed app with 80M+ reported users.

This broad impersonation strategy highlights a significant evolution in the platform’s objectives. Rather than focusing solely on Microsoft 365 access tokens, Kali365 now appears designed to compromise digital identities across multiple environments, enabling attackers to reach cloud resources, messaging platforms, business applications, and enterprise authentication systems. For organizations, this means the threat is no longer limited to a single cloud ecosystem. Any environment that supports device code authentication may potentially become a target.

Device Code Phishing Is Becoming an Industry-Wide Problem

Kali365 is not an isolated threat. Security researchers have observed a growing number of phishing-as-a-service platforms incorporating device code phishing capabilities into their offerings. Other notable examples include Tycoon2FA, Venom, and CYB3R, all of which leverage similar techniques to obtain access tokens while avoiding traditional credential theft methods.

Researchers have recently reported a sharp increase in device code phishing activity, with numerous kits now available to cybercriminals through underground marketplaces. The rapid growth of these platforms reflects a broader shift in attacker strategy. Rather than stealing passwords, threat actors increasingly focus on capturing authenticated sessions, OAuth tokens, and identity artifacts that allow them to bypass conventional security controls entirely.

Why Organizations Must Rethink Identity Security

Device code phishing demonstrates a critical reality of modern cybersecurity: successful authentication does not always indicate legitimate intent. Because these attacks exploit approved authentication workflows, traditional defenses such as strong passwords and MFA may not be sufficient on their own. Defending against this class of attack requires layering additional controls on top of identity systems.

Priority controls for defending against device code phishing
1
Monitor OAuth permissions and token issuance. Continuously watch for unusual access-token grants and newly authorized applications, since these are the artifacts attackers actually capture.
2
Watch for anomalous device registrations. Unexpected devices linking to an account can indicate a device authorization flow completed on an attacker’s behalf.
3
Apply impossible-travel and behavioral detection. Flag logins and token use that occur from improbable locations or deviate from a user’s normal patterns.
4
Train users to question code-entry requests. Employees should treat any unexpected request to enter an authentication code with suspicion, especially when it arrives by email, messaging app, or unsolicited security notification.
5
Treat inbound content and links as untrusted. Because Kali365 lures arrive as messages impersonating trusted services, deep inspection of incoming files, links, and embedded content, such as CyberQuay’s FileDNA approach, can neutralize the delivery mechanism before a victim ever sees the malicious code-entry prompt.

User awareness also remains essential. As phishing-as-a-service platforms continue to mature and expand their target lists, device code phishing is likely to remain one of the most effective methods for bypassing identity-based security controls. Organizations that rely heavily on cloud services must therefore view identity protection, token monitoring, and user education as equally important components of their security strategy.

References

[1]Arctic Wolf. Research on the Kali365 phishing-as-a-service platform and its expansion beyond Microsoft 365 into AWS, Okta, Xerox DocuShare, and Russian online platforms.
[2]CyberQuay, Inc. FileDNA structural content inspection technology