Phishing Awareness

⚠️ Kali365 PhaaS: Device Code Phishing Bypasses MFA

By Sophie Laurent, Hobbyist with a keen interest in password security and online safety, Trusty Password · 26 May 2026 · 7 min read · 1485 words

Cybercriminals no longer need to steal passwords or intercept SMS codes. A new generation of phishing-as-a-service (PhaaS) platforms has emerged that exploits a legitimate authentication flow built into Microsoft 365 — the device code flow — to bypass both passwords and multi-factor authentication entirely. One of the most prominent of these platforms is Kali365, a Telegram-distributed PhaaS toolkit that has been actively targeting businesses since early 2026.

This article explains how device code phishing works, what makes Kali365 particularly dangerous, and — most importantly — how to block this emerging threat before it reaches your organisation.

What Is Device Code Phishing?

Device code authentication is a standard OAuth 2.0 authorisation flow designed for devices that do not have a full web browser — such as smart TVs, gaming consoles, IoT devices, and command-line tools. Instead of opening a browser and logging in directly, these devices display a short alphanumeric code that the user enters on a separate device with a browser. The user navigates to a URL like microsoft.com/devicelogin, enters the code, and completes authentication. The original device then receives an OAuth token that grants access.

This flow is legitimate, useful, and widely used. But it has a critical weakness: the person entering the code has no way of knowing which device or application requested it. An attacker can generate a device code on their end, send it to a victim through a phishing email or fake tech support page, and trick the victim into entering the code on a real Microsoft login page. The victim sees a legitimate Microsoft page, enters the code, completes MFA if prompted, and unknowingly grants the attacker an OAuth token that provides persistent access to their Microsoft 365 account.

What makes device code phishing uniquely dangerous is that it bypasses MFA entirely. The victim goes through the full authentication flow — including any MFA prompts — on the real Microsoft login page. From Microsoft's perspective, the authentication is legitimate. The attacker never touches the password or the MFA code; they simply inherit the resulting session token.

How Kali365 Works

Kali365 is a phishing-as-a-service platform distributed through Telegram channels and dark-web forums. It bundles several capabilities into a single, easy-to-use package that requires minimal technical skill to operate:

The entire platform is designed for scale. A single attacker can launch campaigns targeting hundreds or thousands of organisations simultaneously, using AI-generated lures that are unique to each target. The low cost of entry — subscriptions reportedly start at a few hundred dollars — makes it accessible to a wide range of threat actors.

Why This Is Dangerous for Small Businesses

Device code phishing with tools like Kali365 poses a particular risk to small and medium-sized businesses (SMBs). Large enterprises typically have dedicated security teams, advanced threat detection tools, and Conditional Access policies that can block device code flows. SMBs often operate with minimal IT support and rely on default Microsoft 365 configurations, which leave device code authentication enabled by default.

The consequences of a successful Kali365 attack can be severe. Attackers who gain OAuth token access to a Microsoft 365 account can:

Because device code phishing does not trigger standard "unusual login" alerts — the authentication happens from a legitimate IP address and passes all MFA checks — traditional security monitoring often fails to detect the compromise until the attacker has already extracted significant data.

How to Block Device Code Phishing

Fortunately, device code phishing can be blocked with the right configuration and employee training. Here are the most effective measures:

Disable Device Code Flow

The single most effective defence is to disable the device code authentication flow for your Microsoft 365 tenant if your organisation does not need it. Azure AD administrators can create a Conditional Access policy that blocks device code authentication for all users. If your organisation uses device code flow for specific legitimate purposes (such as automated scripts or IoT devices), you can create exceptions for those specific applications while blocking the flow for all others.

Employee Training

Educate staff never to enter a device code — or any code — from an unexpected email, pop-up, or support page. Legitimate Microsoft device code authentication is initiated by the user, not by an email request. If an email asks you to "enter this code to verify your account," it is almost certainly a phishing attack. Employees should be trained to recognise common phishing lures and to report suspicious messages to their IT department.

Monitor OAuth Token Activity

Regularly audit the OAuth tokens and third-party applications that have been granted access to your Microsoft 365 environment. Revoke any tokens that are unfamiliar, were granted outside of normal business hours, or are associated with applications that should not require access. Azure AD provides tools for monitoring and managing OAuth token grants.

Use Phishing-Resistant MFA

While device code phishing bypasses standard MFA, it does not bypass phishing-resistant MFA methods like FIDO2/WebAuthn passkeys or hardware security keys. Organisations that have deployed passkeys or require FIDO2 authentication are still protected against device code phishing — but very few SMBs have implemented these advanced MFA methods yet.

Additional Security Layers

Using a comprehensive security suite like Kaspersky Premium adds an additional layer of defence against emerging zero-day phishing toolkits. A password manager like NordPass also helps ensure that even if a session is compromised elsewhere, strong unique passwords limit the blast radius.

Conclusion

Kali365 and similar device code phishing platforms represent an evolution in the phishing landscape. By exploiting a legitimate authentication flow, they bypass both passwords and traditional MFA, making them particularly dangerous for organisations that have invested heavily in security awareness training and standard MFA deployment. The good news is that the defence is straightforward: disable device code authentication if you do not need it, train employees to recognise the attack pattern, and consider moving toward phishing-resistant authentication methods like passkeys. Device code phishing is a reminder that as authentication technology evolves, so do the techniques used to bypass it — and that layered, defence-in-depth security remains the only reliable approach.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🛡️ Best Password Generator🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder⚙️ StrongPassFactory🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more