Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge
ID: b6aeb4fc-e122-5904-aa80-6a86cc4d908e
STIX ID: report--b6aeb4fc-e122-5904-aa80-6a86cc4d908e
Feed Name: ReliaQuest Blog
ReliaQuest Threat Research describes the emergence of two phishing toolkits—Jalisco (real-time device-code phishing with lure-generation that harvests OAuth tokens) and OmegaLord (a credential harvester that collects phone numbers alongside credentials)—and a broader AI-powered phishing-as-a-service ecosystem abusing legitimate cloud-hosting to scale attacks that bypass MFA, enroll attacker-controlled devices for persistent access, and enable fast data exfiltration; the report documents observed behavior, abused infrastructure, IOCs, and recommends mitigations such as disabling device-code flows, auditing app registrations, reducing device registration limits, and automating response playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
