Kali365 Hijacks Microsoft Device Login to Harvest OAuth Tokens from US Enterprises
What Happened — The threat group Kali365 is abusing Microsoft’s device‑login flow to obtain OAuth access tokens, allowing them to impersonate legitimate users and pull corporate data from targeted U.S. organizations. The technique sidesteps traditional password‑based defenses and is being delivered via phishing‑laced emails that prompt users to approve a device login request.
Why It Matters for Compliance & Audit Readiness
- This scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) controls that require continuous monitoring of privileged token issuance and revocation.
- Demonstrating evidence that OAuth token requests are logged, reviewed, and tied to approved business purposes satisfies the “least‑privilege” and “access review” criteria auditors look for.
- Verisq’s SOC2 Access Controls capability provides automated collection of device‑login audit logs and token‑usage analytics, giving you a defensible audit trail and real‑time alerts for anomalous token activity.
Who Is Affected — Technology‑focused enterprises, SaaS providers, and any organization that relies on Microsoft Azure AD for single‑sign‑on (SSO) and device authentication.
Recommended Actions
- Map the OAuth token issuance process to SOC 2 CC6.1/CC6.2 controls and enable continuous log collection.
- Implement conditional access policies that require MFA for device‑login flows and restrict token scopes to the minimum necessary.
- Conduct targeted security‑awareness training on phishing emails that request device‑login approvals.
Source: HackRead
Technical Notes
- Attack vector: Phishing emails that trigger Microsoft device‑login prompts, leading to OAuth token theft.
- No public CVE; the abuse leverages legitimate Microsoft authentication endpoints.
- Data types accessed include emails, files stored in OneDrive/SharePoint, and other Office 365 resources.
Source: HackRead