New phishing kits target Microsoft 365 accounts, evade MFA

Cyberattackers have unleashed two sophisticated phishing kits that target Microsoft 365 accounts, exploiting vulnerabilities in multi-factor authentication (MFA) to gain unauthorized access. The Jalisco and OmegaLord toolkits, analyzed by cybersecurity firm ReliaQuest, demonstrate the evolving tactics of threat actors as they adapt to modern security measures.

Jalisco employs a device-code phishing method to trick victims into authorizing an attacker-controlled device to access their Microsoft account. This is achieved through the OAuth 2.0 Device Authorization Grant flow, which allows the attacker to generate fresh device codes in real-time, bypassing Microsoft’s 15-minute code validity period. Once authorized, the attacker can access the victim’s account without needing a username or password.

The Jalisco toolkit also includes a web portal for its operators to manage captured sessions and compromised accounts, showcasing the sophistication of this phishing kit. In some cases, attackers have registered multiple rogue devices on a single compromised account, using seemingly innocuous names containing “Microsoft” or “Windows” to evade suspicion.

OmegaLord, on the other hand, adopts a more traditional approach by masquerading as a PDF reader to collect login credentials and associated phone numbers. This information can be used to intercept or hijack MFA requests or codes, further undermining the security of Microsoft 365 accounts.

The use of device-code phishing has become increasingly common in recent attacks, with Jalisco being just one example of this tactic. ReliaQuest notes that traditional phishing techniques continue to evolve, as seen with OmegaLord’s PDF reader disguise. The explicit targeting of phone numbers and the engineering around MFA controls highlights the determination of threat actors to bypass modern security measures.

The consequences of these attacks can be severe, with attackers exfiltrating sensitive data from compromised accounts within minutes. ReliaQuest warns that defenders may not even realize a breach has occurred until it’s too late. To mitigate this risk, the firm recommends reducing the Entra ID device-registration limit to one or two, blocking device code authentication through Microsoft Entra Conditional Access, and auditing and removing unnecessary app registrations.

In light of these findings, it is essential for organizations to regularly test their defenses against such attacks. By doing so, they can identify vulnerabilities before attackers do, ultimately strengthening their security posture. As the cybersecurity landscape continues to evolve, staying vigilant and proactive will remain crucial in protecting against increasingly sophisticated threats.


Source: Bleeping Computer — 2026-07-14