Device-Code Phishing Mints Persistent Microsoft Tokens
Kali365 turns a normal Microsoft sign-in into lasting access. The victim approves an attacker-provided device code on Microsoft’s own login page, and Microsoft then issues tokens that keep working after the password was never touched. That shifts the problem from a single phish to account-level access across mail, files, and connected cloud apps.
Telemetry shows this is active and scaled. ANY.RUN recorded more than 80 public sessions a week tied to the campaign, with the United States as the main target, and one sandbox session used a SharePoint-themed lure to push victims into the device-code flow. The result is access and refresh tokens that can expose Microsoft 365 email, documents, and cloud resources.
Password-focused phishing checks miss the real compromise here. Once tokens are issued, the attacker can keep using trusted access until those tokens are cut off, even if the original login looks routine.