Skip to main content
عربي
logo

NCSC-TAD-2605-002

Severity Level: Low
Phishing

Reference No.: NCSC-TAD-2605-002CVSS 0

Kali365 Phishing Kit Bypasses MFA and Hijacks Microsoft 365 Sessions

Threat Type:
N/A
TLP:
CLEAR
CVE:
N/A

Overview

An attacker launches a Device Code phishing attack by sending a phishing email that includes a device authentication code and tricks the user into entering it on a legitimate Microsoft sign-in page. Once the code is authenticated, the attacker obtains authentication tokens that provide unauthorized access to the victim’s Microsoft 365 account.

With these tokens, the attacker can maintain continued access to Microsoft services such as Outlook, Teams, and OneDrive without requiring the victim’s password or Multi-Factor Authentication (MFA).

Mitigation and Immediate Actions

  1. 01

    Restrict or disable Device Code Authentication and allow it only for approved business use cases. Before implementing restrictions, review existing usage and exclude emergency administrator accounts to avoid lockouts.

  2. 02

    Regularly review Microsoft account sign-in activity, devices, and active sessions, removing any unauthorized access and resetting credentials whenever suspicious activity is detected.

References