Summary
- Barracuda says Kali365 campaigns have been active in waves since early 2026 against Microsoft 365 environments.
- The service supports device-code phishing and adversary-in-the-middle techniques that can abuse genuine Microsoft sign-in and MFA processes.
- The activity reinforces a wider shift from credential theft towards authenticated sessions, tokens, OAuth, and post-login identity abuse.
A phishing-as-a-service operation known as Kali365 is targeting Microsoft 365 accounts by abusing legitimate authentication processes, allowing victims to complete genuine Microsoft sign-in and multifactor authentication steps while an attacker obtains access to sessions or tokens.
Barracuda said it has observed multiple Kali365 attack waves in recent months, with the platform active since early 2026. Its researchers describe a mix of device-code phishing and adversary-in-the-middle techniques designed to move beyond conventional password harvesting.
In a device-code attack, the victim can be sent to Microsoft’s authentic authentication infrastructure rather than a counterfeit login page. The attacker initiates a device-login request and presents the resulting code to the target, who is persuaded to enter it and complete the legitimate Microsoft authentication process.
If successful, the authentication authorises the attacker’s session rather than simply disclosing the victim’s password. Multifactor authentication can therefore operate exactly as designed while still approving access that the user did not understand they were granting.
Kali365 also supports adversary-in-the-middle techniques in which an attacker-controlled proxy sits between the user and the authentication service. That approach can capture authenticated sessions or tokens after the victim completes a genuine login and MFA flow.
The campaign uses familiar business themes including shared documents, electronic signatures, invoices, voicemail alerts, quarantine reviews, and security notifications. Those lures are conventional; the more consequential change is what happens after the user follows the authentication instructions.
The technique sits within a broader movement in Microsoft 365 phishing that Cyber Insider has already tracked. In August, the Greatness phishing service added device-code and OAuth-consent techniques, similarly shifting account compromise towards tokens and delegated access rather than passwords alone.
This development complicates controls built around the assumption that a phishing attack has to imitate a login page. Website reputation, visual differences, incorrect domains, and warnings against typing credentials into unfamiliar sites all become less useful when the victim is ultimately authenticating on Microsoft’s own infrastructure.
The event trail also changes. An authentication log may contain a technically valid login, completed with the expected credentials and MFA method. The suspicious signal may instead appear in the surrounding context: an unexpected device-code flow, new device registration, unfamiliar OAuth grant, unusual session use, mailbox-rule creation, forwarding changes, or subsequent access to Exchange, SharePoint, OneDrive, or Teams.
That pushes identity monitoring beyond the initial authentication decision. MFA remains an important control, but the relevant question becomes what the user is authenticating and what access is created as a result, rather than simply whether a second factor was presented.
The attack model also puts greater weight on restricting authentication methods that are not required for normal business use. Device-code authentication has legitimate purposes, particularly for devices or interfaces where conventional browser sign-in is inconvenient, but that same flexibility can create a social-engineering route when users are encouraged to approve a code they did not initiate.
Barracuda’s findings describe campaigns seen in its own research and customer environment, not a complete measurement of Kali365 activity. The platform’s continued use nevertheless adds to evidence that phishing services are standardising techniques designed around cloud identity itself.
Password theft has not disappeared, but access to a valid session can be more immediately useful. As authentication becomes stronger, attackers are increasingly trying to manipulate the workflow around that authentication rather than defeat the cryptography or steal the factor outright.




