logo

Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts

ID: 8d447523-0df6-55ea-8e92-7cffd98a520d

STIX ID: report--8d447523-0df6-55ea-8e92-7cffd98a520d

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: Aminu Abdullahi

...
...

ReliaQuest researchers disclosed two active phishing toolkits—Jalisco and OmegaLord—targeting Microsoft 365 environments by defeating MFA: Jalisco generates real-time OAuth device codes to capture session tokens, and OmegaLord simulates login pages to steal credentials and phone numbers for MFA interception. Attackers can persist by registering malicious devices that refresh tokens even after password resets, and AI-powered phishing-as-a-service platforms are accelerating the scale and sophistication of these campaigns, prompting recommendations to restrict device-code authentication and strengthen identity controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.