Kali365 abuses the current OAuth device code flow on Microsoft accounts in a sophisticated attempt to dupe users into signing into their accounts

source https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication