Multi-factor authentication (MFA) has been considered one of the most effective protection measures against account takeovers for years. Many organizations rely on an additional security feature — such as an authenticator app or SMS — to prevent threat actors from accessing corporate accounts.
But cybercriminals are constantly evolving their methods. With Kali365, security researchers and authorities are currently observing an attack method that shows that even proven protection mechanisms are not always sufficient. Companies that use Microsoft 365 in particular should follow developments closely and review their security measures.
What is Kali365?
Kali365 is a so-called phishing-as-a-service platform. Put simply, it is a ready-made toolbox that cybercriminals can use to carry out deceptively real attacks on Microsoft 365 users.
While classic phishing campaigns aim to steal usernames and passwords, Kali365 takes a different approach. The attackers exploit legitimate login processes from Microsoft and try to obtain access tokens. These tokens serve as digital access authorization and enable access to various Microsoft 365 services.
The key difference is that even if multi-factor authentication has been successfully performed, attackers may still be able to access the account with a captured access token.
Why is this attack method particularly dangerous?
Many employees have learned to watch out for suspicious links or fake login pages. However, Kali365 partially uses genuine Microsoft services and legitimate login processes. This makes the attacks appear much more credible than conventional phishing attempts.
In addition, such phishing-as-a-service offers significantly reduce the technical hurdle for cybercriminals. Threat actors do not have to develop the necessary tools themselves, but can fall back on platforms that have already been prepared.
As a result, the number and quality of such attacks is likely to continue to increase.
How does a typical Kali 365 attack work?
A Kali365 attack usually begins with a phishing email, such as an alleged document release or Teams notification. The user is prompted to enter a device code or confirm a login.
The special feature: The registration takes place via a real Microsoft website. The user logs in regularly and confirms the multi-factor authentication as usual. In the background, however, the attacker has already started a so-called device code flow.
With the confirmation, the user unintentionally authorizes one of the attackers’ devices. Microsoft then issues valid access permissions, which are transmitted directly to the attacker. This can then access Microsoft 365 services such as Outlook, Teams, OneDrive or SharePoint – without knowing the user’s password.
This is exactly what makes Kali365 so dangerous: The attack abuses a legitimate Microsoft login process and can thus bypass even proven protective measures such as multi-factor authentication.
Which systems are affected?
Basically, all organizations that use Microsoft 365 are affected. The focus is particularly on:
If an account is compromised, threat actors can access emails, files, and internal communication data. In addition, compromised accounts are often used to carry out further phishing attacks within the company or against business partners.
How can such attacks be recognised?
There are a few red flags that businesses and users should be aware of. This includes unexpected requests to sign in to Microsoft 365 or requests to enter device codes or to release a sign-in that was not initiated by the user. Unusual login attempts from unknown regions or at unusual times can also indicate a potential attack.
In addition, suspicious activity within Outlook, OneDrive or Teams should be carefully monitored, especially if files, emails or settings are changed for no apparent reason. Since the registration procedures used often seem legitimate, the following applies as a general rule: Every unexpected registration or release request should be critically examined before reacting to it.
What protective measures are recommended?
The good news is that even though Kali365 is targeting modern authentication methods, companies can significantly reduce their risk.
Key measures include:
Above all, it is important not to consider MFA as the sole protective measure. Modern attacks show that a multi-layered approach to security is necessary.
Kali365 highlights an important trend in cybercrime: threat actors are increasingly focused on bypassing established protections rather than attacking them outright.
For companies, this means that even supposedly well-protected Microsoft 365 environments should be regularly checked and monitored. The combination of technical protective measures, active monitoring and sensitized employees remains the most effective protection against modern phishing attacks.
Do you want to stay informed about current threats and security vulnerabilities?
Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.
Sources & Further Information