{"id":879,"date":"2026-06-04T11:15:19","date_gmt":"2026-06-04T05:45:19","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=879"},"modified":"2026-08-19T11:15:54","modified_gmt":"2026-08-19T05:45:54","slug":"kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/","title":{"rendered":"Kali365 Phishing Kit Expands Beyond Microsoft 365 Through Device Code OAuth Attacks"},"content":{"rendered":"<p>The Kali365 phishing kit has expanded beyond its original focus on Microsoft 365, with researchers observing attacks targeting AWS, Okta, Xerox DocuShare, MAX Messenger, GMX, Mail.ru, Yandex Disk, and Odnoklassniki. The expansion highlights how attackers are increasingly targeting cloud identities and authentication workflows rather than relying solely on credential theft.<\/p>\n<p>Unlike traditional phishing campaigns that steal usernames and passwords, Kali365 uses device code phishing to abuse legitimate OAuth authentication processes. Victims are tricked into completing a valid sign-in flow, resulting in OAuth access tokens being issued to an attacker-controlled session.<\/p>\n<p>The broader targeting suggests that device code phishing is no longer limited to Microsoft-centric environments. As organizations continue to adopt cloud applications, SSO platforms, and federated identity services, OAuth token theft and <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-itdr-identity-threat-detection-response-hexnode\/\">identity-focused attacks<\/a> are becoming increasingly important considerations for security teams.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen phishing defense using Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How Kali365 Abuses Device Authorization Flows<\/h2>\n<p>The Kali365 phishing kit uses device code phishing to abuse the OAuth Device Authorization Grant workflow. This authentication method is commonly used by devices with limited input capabilities, such as smart TVs, IoT devices, and printers, where entering credentials directly may not be practical.<\/p>\n<p>In a legitimate workflow, a user receives a device code and completes authentication through a trusted login portal. Once approved, the requesting device receives OAuth tokens that allow access to authorized resources.<\/p>\n<p>Kali365 operators exploit this process by generating legitimate device authorization requests and convincing victims to complete them on the attacker\u2019s behalf.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Attack flow - <\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t\n<ol>\n<li>The attacker initiates a legitimate device authorization request for a targeted cloud service.<\/li>\n<li>The victim receives a phishing lure with instructions to enter a provided device code.<\/li>\n<li>The victim opens a legitimate authentication page operated by the service provider.<\/li>\n<li>The victim completes authentication and any required <a href=\"https:\/\/www.hexnode.com\/blogs\/reinforcing-cybersecurity-with-multi-factor-authentication-mfa\/\">MFA<\/a> challenge.<\/li>\n<li>OAuth access tokens are issued to the attacker-controlled session.<\/li>\n<li>The attacker gains access to the targeted service without collecting the victim\u2019s password.     \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/li>\n<\/ol>\n<h3>Why MFA Does Not Stop the Attack<\/h3>\n<p>Many traditional phishing attacks attempt to steal credentials or MFA codes. In device code phishing, the victim completes the authentication process and approves the authorization request themselves.<\/p>\n<p>As a result, the identity provider issues valid OAuth tokens through a legitimate workflow. The attacker gains access without intercepting credentials or MFA codes, making OAuth token theft difficult to detect through credential-focused defenses.<\/p>\n<h3>Kali365 Expands Beyond Microsoft 365<\/h3>\n<p>Earlier reporting primarily associated Kali365 with Microsoft 365-targeted campaigns. Recent research from Arctic Wolf indicates that the platform has expanded its targeting to include a broader set of cloud and identity services.<\/p>\n<p>Reported targets include AWS, Okta, Xerox DocuShare, MAX Messenger, GMX, Mail.ru, Yandex Disk, and Odnoklassniki.<\/p>\n<p>Researchers also identified approximately 126 active malicious hosts associated with the infrastructure during May. The findings suggest Kali365 is expanding beyond Microsoft 365 and appears to be adapting to services that rely on OAuth-based authentication.<\/p>\n<h3>Phishing-as-a-Service Capabilities<\/h3>\n<p>Kali365 also reflects the growing sophistication of phishing-as-a-service platforms. According to public reporting, the service includes AI-generated phishing lures, automated campaign templates, real-time tracking dashboards, and OAuth token capture capabilities.<\/p>\n<p>These features reduce the technical expertise required to launch identity-focused attacks and allow operators to scale campaigns more efficiently. For defenders, Kali365 reinforces the need to monitor authentication workflows, OAuth activity, and token usage alongside traditional credential-based attack indicators.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-essentials.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity essentials for any organization<\/h4><p>Core cybersecurity essentials for protecting data, devices, and operations.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-essentials-for-any-organization\/\" aria-label=\"Cybersecurity essentials for any organization\"><\/a><\/div><\/div><\/div>\n<h2><span class=\"TextRun SCXW2444170 BCX0\" lang=\"EN-GB\" xml:lang=\"EN-GB\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW2444170 BCX0\" data-ccp-parastyle=\"heading 2\">Operational Summary<\/span><\/span><span class=\"EOP Selected SCXW2444170 BCX0\" data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<table style=\"width: 86.4958%;\">\n<thead>\n<tr>\n<th style=\"width: 30.5494%; text-align: left;\">Component<\/th>\n<th style=\"width: 72.8901%; text-align: left;\">Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 30.5494%;\">Threat Type<\/td>\n<td style=\"width: 72.8901%;\">Phishing-as-a-Service (PhaaS)<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.5494%;\">Primary Technique<\/td>\n<td style=\"width: 72.8901%;\">Device code phishing<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.5494%;\">Target Asset<\/td>\n<td style=\"width: 72.8901%;\">Cloud identities and OAuth access tokens<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.5494%;\">Authentication Impact<\/td>\n<td style=\"width: 72.8901%;\">MFA protections can be circumvented when users complete the authentication process<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.5494%;\">Reported Targets<\/td>\n<td style=\"width: 72.8901%;\">Microsoft 365, AWS, Okta, Xerox DocuShare, and other reported services<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.5494%;\">Attacker Objective<\/td>\n<td style=\"width: 72.8901%;\">OAuth token theft and unauthorized account access<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Risk and Operational Impact<\/h2>\n<p>The expansion of the Kali365 phishing kit highlights how attackers are increasingly abusing authentication workflows rather than relying solely on credential theft. For organizations that rely on cloud services and centralized identity platforms, this creates new challenges around token security and access control.<\/p>\n<h3>Device Code Phishing Changes the Threat Model<\/h3>\n<p>Unlike traditional <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing attacks<\/a>, device code phishing abuses legitimate authentication workflows to obtain authorized access tokens, reducing the effectiveness of credential-focused defenses.<\/p>\n<h3>OAuth Token Theft Can Expand Access<\/h3>\n<p>A successful compromise can provide access to cloud resources associated with the affected account, depending on the permissions granted to that identity.<\/p>\n<h3>Legitimate Authentication Can Hinder Detection<\/h3>\n<p>Victims authenticate through legitimate login portals and may complete valid MFA challenges when required, making malicious activity difficult to distinguish from normal user behavior.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet.png?format=webp\" class=\"resource-box__image\" alt=\"hexnode xdr infosheet\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"hexnode xdr infosheet\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode XDR Info Sheet\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Gain actionable threat intelligence and streamline security response through unified endpoint visibility.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/hexnode-xdr-info-sheet\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How to Reduce Exposure and Mitigate Risk<\/h2>\n<p>Organizations should review how device authorization workflows are used within their environment and determine whether the device code flow is required for business operations.<\/p>\n<p>As identity-focused attacks continue to evolve, security teams should focus on strengthening visibility into authentication activity and reducing opportunities for unauthorized token issuance.<\/p>\n<h3>Recommended actions include:<\/h3>\n<ul>\n<li>Monitor unusual device authorization requests and OAuth consent activity.<\/li>\n<li>Review conditional access policies for high-risk applications.<\/li>\n<li>Restrict access from unmanaged or non-compliant devices where appropriate.<\/li>\n<li>Implement phishing-resistant authentication methods such as FIDO2 security keys.<\/li>\n<li>Establish procedures for rapid OAuth token revocation during incident response.<\/li>\n<li>Hunt for suspicious token usage, anomalous sign-in activity, and unexpected cloud application access.<\/li>\n<\/ul>\n<p>Organizations should also ensure security awareness programs address device code phishing techniques, which differ from traditional credential-harvesting attacks.<\/p>\n<h2>How Hexnode Can Help<\/h2>\n<p>While Kali365 focuses on identity abuse rather than endpoint exploitation, endpoint visibility remains important during investigation and response.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/\">Hexnode<\/a> can help organizations enforce device compliance requirements and improve visibility into the security posture of managed devices across the environment.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\">Hexnode XDR<\/a> can help security teams investigate suspicious activity by correlating endpoint telemetry, security events, and threat data through a unified detection, investigation, and response workflow.<\/p>\n<h2>Conclusion<\/h2>\n<p>The Kali365 phishing kit highlights how attackers are increasingly abusing legitimate authentication workflows to facilitate OAuth token theft and unauthorized access. As the Kali365 phishing kit expands beyond Microsoft 365, organizations should pay closer attention to identity activity and token-based threats.<\/p>\n<p>Reducing risk requires layered controls, including identity monitoring, phishing-resistant authentication, conditional access policies, and endpoint visibility to support faster detection and response.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen visibility across every endpoint<\/h5><p>Start a free trial to experience unified threat detection and investigation workflows.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How is device code phishing different from traditional phishing?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Traditional phishing campaigns attempt to steal usernames, passwords, or MFA codes. Device code phishing abuses legitimate authentication workflows, allowing attackers to obtain authorized OAuth tokens without directly collecting user credentials.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can password resets stop OAuth token-based attacks?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not always. If valid OAuth tokens have already been issued, attackers may retain access until the affected tokens expire or are revoked. Organizations should include token revocation procedures in their incident response plans.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should security teams monitor to detect device code phishing activity?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Security teams should monitor unusual device authorization requests, OAuth consent activity, anomalous sign-in behavior, and unexpected access to cloud applications. Correlating identity, endpoint, and cloud telemetry can improve detection and investigation efforts.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Kali365 phishing kit has expanded beyond its original focus on Microsoft 365, with researchers&#8230;<\/p>\n","protected":false},"author":5,"featured_media":882,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,19],"class_list":["post-879","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-cloud-and-saas","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Kali365 Phishing Kit Expands Beyond Microsoft 365<\/title>\n<meta name=\"description\" content=\"The Kali365 phishing kit is expanding beyond Microsoft 365, using device code phishing and OAuth token theft to target cloud identities.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kali365 Phishing Kit Expands Beyond Microsoft 365\" \/>\n<meta property=\"og:description\" content=\"The Kali365 phishing kit is expanding beyond Microsoft 365, using device code phishing and OAuth token theft to target cloud identities.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-04T05:45:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T05:45:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/kali365-phishing-kit.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Kali365 Phishing Kit Expands Beyond Microsoft 365 Through Device Code OAuth Attacks\",\"datePublished\":\"2026-06-04T05:45:19+00:00\",\"dateModified\":\"2026-08-19T05:45:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/\"},\"wordCount\":1204,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/kali365-phishing-kit.jpeg?format=webp\",\"articleSection\":[\"Phishing\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/\",\"name\":\"Kali365 Phishing Kit Expands Beyond Microsoft 365\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/kali365-phishing-kit.jpeg?format=webp\",\"datePublished\":\"2026-06-04T05:45:19+00:00\",\"dateModified\":\"2026-08-19T05:45:54+00:00\",\"description\":\"The Kali365 phishing kit is expanding beyond Microsoft 365, using device code phishing and OAuth token theft to target cloud identities.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/kali365-phishing-kit.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/kali365-phishing-kit.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"kali365 phishing kit\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kali365 Phishing Kit Expands Beyond Microsoft 365 Through Device Code OAuth Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kali365 Phishing Kit Expands Beyond Microsoft 365","description":"The Kali365 phishing kit is expanding beyond Microsoft 365, using device code phishing and OAuth token theft to target cloud identities.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Kali365 Phishing Kit Expands Beyond Microsoft 365","og_description":"The Kali365 phishing kit is expanding beyond Microsoft 365, using device code phishing and OAuth token theft to target cloud identities.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-04T05:45:19+00:00","article_modified_time":"2026-08-19T05:45:54+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/kali365-phishing-kit.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Kali365 Phishing Kit Expands Beyond Microsoft 365 Through Device Code OAuth Attacks","datePublished":"2026-06-04T05:45:19+00:00","dateModified":"2026-08-19T05:45:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/"},"wordCount":1204,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/kali365-phishing-kit.jpeg?format=webp","articleSection":["Phishing","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/","url":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/","name":"Kali365 Phishing Kit Expands Beyond Microsoft 365","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/kali365-phishing-kit.jpeg?format=webp","datePublished":"2026-06-04T05:45:19+00:00","dateModified":"2026-08-19T05:45:54+00:00","description":"The Kali365 phishing kit is expanding beyond Microsoft 365, using device code phishing and OAuth token theft to target cloud identities.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/kali365-phishing-kit.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/kali365-phishing-kit.jpeg?format=webp","width":1340,"height":700,"caption":"kali365 phishing kit"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/kali365-phishing-kit-expands-beyond-microsoft-365-through-device-code-oauth-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Kali365 Phishing Kit Expands Beyond Microsoft 365 Through Device Code OAuth Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=879"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/879\/revisions"}],"predecessor-version":[{"id":884,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/879\/revisions\/884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/882"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}