ANY.RUN telemetry records more than 80 public sessions tied to the campaign each week, with the United States the main geographic target.
How Kali365 weaponizes Microsoft device authentication
Kali365 is a device-code phishing kit built to abuse legitimate Microsoft authentication. The campaign uses attacker-controlled device codes that victims are asked to enter on Microsoft's real device login portal. Once a user approves the code on Microsoft's page, attackers can obtain OAuth access and refresh tokens, giving them persistent entry to Microsoft 365 email, documents, and cloud resources.
The campaign unfolds in three distinct stages: (1) a lure page impersonating trusted services such as SharePoint, OneDrive, or DocuSign; (2) a redirect into Microsoft's genuine device authentication portal where the victim is prompted to enter an attacker-provided code; and (3) acquisition of tokens that allow continued access to corporate mail, internal files, and cloud services. ANY.RUN’s sandboxes captured a SharePoint-themed lure in one recorded session, illustrating the simple social-engineering play used to start the flow.
What a single approved device code can cost a US company
A single approved device-code request can expand into a broader Microsoft 365 compromise. The source lists several concrete business risks for US organizations: financial fraud via invoice manipulation and business email compromise; exposure of corporate email, customer data, and confidential documents; operational disruption to communications and business processes; higher incident response costs stemming from delayed detection; and compliance and reputational risk if regulated or customer data is exposed.
Because authentication occurs on Microsoft's legitimate page, the activity often looks routine initially, which can give attackers more time to misuse trusted access before incidents are confirmed. The advisory highlights that fewer obvious phishing indicators may delay detection and complicate containment.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage →Detection and response: three priorities ANY.RUN recommends
ANY.RUN frames mitigation of Kali365 around three priorities that move beyond email filtering.
- Expand detection with actionable phishing intelligence: Kali365 operators rotate domains, URLs, and hosting, so indicators from one case can become stale quickly. ANY.RUN offers threat feeds (STIX/TAXII, API, SDK) drawn from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals; each indicator links back to the session where it appeared to give defenders context for verification and hunting.
- Give Tier 1 the evidence needed to act: The real warning signs often appear before the Microsoft login — in lures, redirects, browser behavior, scripts, and attacker-controlled infrastructure. ANY.RUN’s Interactive Sandbox combines manual interaction and automated analysis to reveal the full chain from phishing page through the transition into Microsoft authentication, and auto-generated reports bundle verdicts, IOCs, TTPs, and behavioral evidence for faster handoff and containment.
- Turn threat research into proactive defense: Teams can explore Kali365 activity in ANY.RUN’s Threat Intelligence Lookup to see related infrastructure, lure screenshots, and targeting patterns. Manually compiled Threat Intelligence Reports include investigation findings and lookup queries that teams can apply to hunting, detection reviews, and incident enrichment to track emerging patterns before they reach the environment.
Operational gains reported by organizations using the sandbox
Organizations using ANY.RUN have reported specific operational improvements tied to faster detection and richer evidence: 94% faster threat triage; up to 21 minutes less mean time to repair (MTTR) per case; up to 20% lower Tier 1 workload; and 30% fewer Tier 1-to-Tier 2 escalations. ANY.RUN frames these reductions as ways to shrink the window in which token abuse can expand into fraud, data exposure, or operational disruption.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Expect the attack to look like legitimate authentication at Microsoft’s device login page; focus on detecting the earlier stages (lures, redirects, scripts) and integrating fresh phishing IOCs into SIEM, SOAR, TIP, firewalls, and blocking layers.
- Procurement and security leadership: Vendor-provided threat feeds and sandbox evidence can speed triage and reduce Tier 1 load, but defenders must adopt flows that deliver fresh indicators into enforcement points rather than rely on static lists.
- End users and business staff: Social-engineering lures will continue to mimic trusted services such as SharePoint and OneDrive; handing over an attacker-provided device code on Microsoft’s real login page is the decisive gesture that enables token theft.
Kali365 highlights a narrow but dangerous truth: when the login page itself is used as the authentication stage, traditional email filters are necessary but insufficient. The practical work for CISOs and SOCs is set — detect the lure and redirect patterns, enroll timely intelligence into enforcement systems, and shorten the time between suspicious activity and containment so a single approved device code cannot become a company-wide breach.



