// Microsoft 365HIGH
Kali365, a phishing-as-a-service platform, is conducting a sustained campaign targeting US companies with device code phishing attacks against Microsoft 365 accounts. The attack abuses Microsoft's legitimate OAuth authentication flow to obtain access and refresh tokens without directly stealing passwords, enabling attackers to compromise corporate email, documents, and cloud services. Threat intelligence shows over 80 phishing sessions per week targeting US organizations across manufacturing, technology, healthcare, government, consulting, and managed service provider sectors.
- Kali365 Exploits Microsoft Device Login to Access US Corporate D(opens in a new tab)
- Kali365 Phishing-as-a-Service Exploits Microsoft 365 Device Code(opens in a new tab)
// Get alerts for Microsoft 365