HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Kali365 Hijacks Microsoft Device Login to Harvest OAuth Tokens from US Enterprises

Kali365 is abusing Microsoft’s device‑login flow to steal OAuth tokens via phishing, enabling unauthorized access to corporate data. The technique highlights gaps in access‑control monitoring that SOC 2 readiness programs must address.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
hackread.com

Kali365 Hijacks Microsoft Device Login to Harvest OAuth Tokens from US Enterprises

What Happened — The threat group Kali365 is abusing Microsoft’s device‑login flow to obtain OAuth access tokens, allowing them to impersonate legitimate users and pull corporate data from targeted U.S. organizations. The technique sidesteps traditional password‑based defenses and is being delivered via phishing‑laced emails that prompt users to approve a device login request.

Why It Matters for Compliance & Audit Readiness

  • This scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) controls that require continuous monitoring of privileged token issuance and revocation.
  • Demonstrating evidence that OAuth token requests are logged, reviewed, and tied to approved business purposes satisfies the “least‑privilege” and “access review” criteria auditors look for.
  • Verisq’s SOC2 Access Controls capability provides automated collection of device‑login audit logs and token‑usage analytics, giving you a defensible audit trail and real‑time alerts for anomalous token activity.

Who Is Affected — Technology‑focused enterprises, SaaS providers, and any organization that relies on Microsoft Azure AD for single‑sign‑on (SSO) and device authentication.

Recommended Actions

  • Map the OAuth token issuance process to SOC 2 CC6.1/CC6.2 controls and enable continuous log collection.
  • Implement conditional access policies that require MFA for device‑login flows and restrict token scopes to the minimum necessary.
  • Conduct targeted security‑awareness training on phishing emails that request device‑login approvals.

Source: HackRead

Technical Notes

  • Attack vector: Phishing emails that trigger Microsoft device‑login prompts, leading to OAuth token theft.
  • No public CVE; the abuse leverages legitimate Microsoft authentication endpoints.
  • Data types accessed include emails, files stored in OneDrive/SharePoint, and other Office 365 resources.

Source: HackRead

📰 Original Source
https://hackread.com/kali365-exploit-microsoft-device-login-access-us-data/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →