← Back to Tech & Science

New Kali365 Phishing Kit Exploits Microsoft Authentication to Target U.S. Firms

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

NEW YORK — A sophisticated phishing campaign known as Kali365 is actively targeting United States organizations by weaponizing legitimate Microsoft authentication protocols to steal corporate credentials and access sensitive data.

The attack, identified on August 5, 2026, utilizes a malicious kit designed to intercept device codes generated during the Microsoft login process. Instead of relying solely on traditional credential harvesting forms that mimic login pages, Kali365 operators deploy attacker-controlled devices or scripts that generate unique authorization tokens. When unsuspecting employees enter these codes into their browsers as part of standard multi-factor authentication flows, they inadvertently grant attackers direct access to corporate email inboxes, file servers, and cloud-based resources.

Security researchers have confirmed the campaign is focused specifically on American entities across various sectors. The operators behind Kali365 aim to establish persistent footholds within victim networks to facilitate financial fraud, disrupt critical business operations, or exfiltrate proprietary intellectual property. By leveraging trusted Microsoft infrastructure for authentication verification, the attack bypasses many conventional perimeter defenses that flag suspicious login attempts from unknown locations.

The mechanism relies on social engineering tactics where employees are tricked into believing they must authorize a new device to maintain access to their work accounts. Once the victim inputs the code provided by the attacker's system, Microsoft validates the request as legitimate because it originates from an authorized authentication flow. This grants the Kali365 operators immediate entry without requiring them to crack passwords or bypass standard encryption measures.

Affected organizations face significant risks including unauthorized transfer of funds via compromised email accounts and the theft of sensitive documents stored in cloud environments. The nature of the attack makes detection difficult, as the initial access appears to come from a valid user session rather than an external breach attempt. Network administrators may only discover the intrusion after observing anomalous data transfers or unexpected changes to system configurations.

Cybersecurity experts warn that standard password resets are insufficient to stop this specific threat vector if attackers have already established authorized sessions through stolen device codes. Organizations must revoke active tokens and audit recent authentication logs immediately upon suspicion of compromise. The Kali365 group has not been publicly identified, nor have any arrests or takedown operations been announced as of the initial discovery.

Questions remain regarding the full scope of the campaign and whether other international targets are being pursued alongside U.S. organizations. As Microsoft updates its authentication frameworks to address these specific vulnerabilities, security analysts anticipate that threat actors will likely adapt their techniques to exploit new weaknesses in identity management systems.

Discussion

0 / 2000