logo

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

ID: 464954ec-43db-55cd-872c-9faa94e39188

STIX ID: report--464954ec-43db-55cd-872c-9faa94e39188

Feed Name: KnowBe4 Blog

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: KnowBe4 Team

...
...

ReliaQuest researchers have identified two phishing toolkits that bypass MFA: “Jalisco,” a device-code phishing platform that provisions fresh OAuth device codes in real time (including lure-generation to neutralize TTL protections), and “OmegaLord,” a JavaScript credential harvester that unusually also collects phone numbers to intercept or hijack MFA. Both tools are being used in the wild and, when paired with AI-powered phishing-as-a-service, enable account takeover, persistence in Microsoft 365/Entra ID tenants, and rapid SaaS data exfiltration for extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.