Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Summary

A new phishing kit named Kali365 is exploiting Microsoft's authentication system to gain unauthorized access to US companies. It leverages attacker-controlled device codes that victims approve on legitimate Microsoft login pages, granting attackers access to sensitive data and cloud resources.

IFF Assessment

FOE

This is bad news for defenders as a new tool is weaponizing legitimate authentication mechanisms to facilitate data theft and fraud.

Defender Context

Defenders should be aware of Kali365's technique of abusing Microsoft authentication flows, specifically the device code authorization process. This highlights the need for robust monitoring of authentication logs for suspicious device approvals and the potential for credential compromise even when legitimate-looking MFA prompts are used.

Read Full Story →