Skip to content
Kali365 is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Instead of directing victims to a fake login form, the phishkit sends them to a real Microsoft page, where they authorize access using an attacker-controlled device code. This makes the attack harder for analysts to spot and more dangerous for the business. By obtaining OAuth acc...
Kali365 Targets US Organizations with Data Theft via Device Code Phishing | Huntaegis