New phishing kits target Microsoft 365 accounts, evade MFA

Microsoft 365 Users at Risk as New Phishing Kits Emerge, Evading Multi-Factor Authentication

Cybersecurity researchers have discovered two sophisticated phishing kits, Jalisco and OmegaLord, designed to target Microsoft 365 accounts and evade multi-factor authentication (MFA) protections. These tools demonstrate how threat actors are continually adapting their tactics to stay ahead of modern security defenses.

Jalisco uses a technique called device-code phishing, which tricks victims into authorizing an attacker-controlled device to access their Microsoft account. This is achieved by exploiting the OAuth 2.0 Device Authorization Grant flow, which allows devices to be granted temporary access to user accounts without requiring passwords or other credentials. The threat actor convinces the victim to sign in to the legitimate Microsoft login page and enter a generated device authorization code, thereby approving the attacker-controlled device.

Once authorized, the attacker can access the victim’s account without needing their username or password. What’s more, Jalisco generates fresh Microsoft OAuth device codes automatically when a victim opens the phishing page, bypassing Microsoft’s 15-minute validity period for device codes specifically designed to combat device-code phishing attacks.

The researchers note that in some cases, attackers register multiple rogue devices on a single compromised account, often using innocuous names containing “Microsoft” or “Windows” to avoid raising suspicion. After gaining access, the attackers search SharePoint and other SaaS services for valuable data, exfiltrate it within minutes, and then follow up with extortion demands and threats of data leakage.

OmegaLord is a more conventional phishing tool that uses a fake PDF Reader login page to steal email addresses, passwords, and phone numbers. The explicit targeting of phone numbers highlights how threat actors are engineering around MFA protections by collecting this sensitive information.

These new phishing kits join a long list of similar tools designed to exploit device-code authentication methods. ReliaQuest researchers recommend that organizations take immediate action to reduce the risk of these attacks. This includes reducing the Entra ID device-registration limit, blocking device code authentication through Microsoft Entra Conditional Access, restricting the OAuth Device Authorization grant in Okta, and auditing and removing unnecessary app registrations.

In today’s threat landscape, it’s essential for security teams to stay vigilant and proactive. By regularly testing their defenses and identifying vulnerabilities, organizations can reduce the likelihood of successful attacks.


Source: Bleeping Computer — 2026-07-14