🚨 Kali365 Device Code Phishing – .de Domain Spike Alert
Over the past week, we’ve observed a significant surge in .de domains leveraged in Kali365‑linked device‑code phishing campaigns. These attacks abuse Microsoft OAuth flows, tricking users into entering verification codes on fake portals.
🔎 Detection tip:
Look for RemoteUrl domains with the following pattern:
<10‑alphanumeric>.<brand>.de
Example:
9jtr5qfz9o[.]memorablebrands[.]de
This helps flag suspicious .de domains hosting device‑auth phishing pages. Sharing detections across the defender community is key to staying ahead of this evolving trend. 🫡
#Cybersecurity #Kali365 #DeviceCodePhishing #DefenderXDR