logo

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

ID: b6aeb4fc-e122-5904-aa80-6a86cc4d908e

STIX ID: report--b6aeb4fc-e122-5904-aa80-6a86cc4d908e

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2026-07-14

Date Updated: 2026-07-19

...
...

ReliaQuest Threat Research describes the emergence of two phishing toolkits—Jalisco (real-time device-code phishing with lure-generation that harvests OAuth tokens) and OmegaLord (a credential harvester that collects phone numbers alongside credentials)—and a broader AI-powered phishing-as-a-service ecosystem abusing legitimate cloud-hosting to scale attacks that bypass MFA, enroll attacker-controlled devices for persistent access, and enable fast data exfiltration; the report documents observed behavior, abused infrastructure, IOCs, and recommends mitigations such as disabling device-code flows, auditing app registrations, reducing device registration limits, and automating response playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.