Kali365 Phishing Attack Uses Microsoft Login System to Target Businesses
A new phishing campaign known as Kali365 is targeting businesses by abusing a legitimate Microsoft login process to steal access to company accounts. Instead of creating a fake login page, attackers trick employees into approving a real Microsoft authentication request, allowing criminals to gain access to email accounts, documents, and other cloud resources.
The attack relies on a technique called device code phishing. Victims are first shown a fake page that appears to be connected to a trusted service, such as Microsoft SharePoint, OneDrive, or DocuSign. The page then directs them to Microsoft’s actual login website and provides a special code. When the victim enters the code and approves the request, attackers may receive digital access tokens that allow them to continue accessing the account.
Because the login happens on a legitimate Microsoft website, the activity may not immediately appear suspicious. This makes the attack more difficult to detect and gives criminals more time to misuse the stolen access. Once inside, attackers could view emails, access company files, steal sensitive information, or use compromised accounts to carry out additional fraud.
The potential damage to businesses can be significant. Attackers with access to employee accounts may manipulate invoices, conduct payment scams, steal confidential company information, or disrupt normal operations. Organizations may also face legal, regulatory, and reputation problems if customer or business data is exposed.
The Kali365 campaign shows how cybercriminals are shifting away from traditional fake login pages and finding new ways to abuse trusted services. Since the authentication process itself is legitimate, security teams need to look beyond simple phishing detection and monitor unusual account activity, suspicious login behavior, and unexpected access requests.
To reduce the risk of these attacks, companies should strengthen their identity security practices. This includes using multi-factor authentication, monitoring unusual sign-in activity, limiting account permissions, and educating employees about suspicious login requests. Employees should be cautious when asked to enter codes or approve sign-ins they did not personally start.
Security teams should also use updated threat information to identify suspicious websites, domains, and attack methods before they spread. Detecting the early stages of a phishing attempt can help prevent attackers from gaining access to valuable business systems.
The Kali365 campaign highlights a growing challenge for organizations: attackers are increasingly targeting the tools and services businesses trust. Protecting against these threats requires strong authentication controls, careful monitoring, and quick action when suspicious activity is discovered.






