Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: US-based enterprises using Microsoft 365
Incident: Active campaign utilizing the Kali365 phishing kit to steal Microsoft 365 access tokens.
Impact: Unauthorized persistent access to corporate email, documents, and cloud resources, enabling data exfiltration and financial fraud.
Attacker: Unidentified threat actors
Analysis: Kali365 abuses the Microsoft device code flow to steal OAuth tokens by directing victims to legitimate login pages with attacker-controlled codes. This method effectively bypasses many traditional email filters because the final authentication occurs on a trusted Microsoft domain. Once access and refresh tokens are acquired, attackers maintain persistent access to corporate M365 environments.
Recommendations: Deploy phishing-resistant MFA, such as FIDO2 keys, to prevent token theft.; Monitor Microsoft Entra ID logs for unusual or high volumes of device code authentication requests.; Train employees to never enter codes provided by third parties into official authentication portals.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source