Researchers have identified two advanced phishing toolkits, Jalisco and OmegaLord, actively targeting Microsoft 365 users by exploiting legitimate authentication processes and sophisticated social engineering techniques to bypass multi-factor authentication (MFA). Jalisco abuses the OAuth 2.0 Device Authorization Grant (Device Code Flow) to trick users into authorizing attacker-controlled devices without requiring their passwords, while OmegaLord impersonates a PDF reader to harvest Microsoft 365 credentials and users' phone numbers, potentially facilitating MFA bypass. Once access is obtained, attackers rapidly compromise cloud resources such as SharePoint, exfiltrate sensitive organizational data within minutes, and may subsequently launch extortion campaigns. These evolving phishing techniques highlight the growing shift from traditional credential theft toward the abuse of trusted authentication mechanisms, emphasizing the need for stronger identity security controls, continuous monitoring, and user awareness.
The Jalisco phishing kit exploits the OAuth 2.0 Device Authorization Grant (Device Code Flow), a legitimate authentication feature designed for devices with limited input capabilities. The toolkit dynamically generates valid Microsoft device authorization codes and presents them to victims through phishing pages. Victims are socially engineered into entering these codes on Microsoft's legitimate authentication portal, unknowingly authorizing an attacker-controlled device. This method completely bypasses password collection and significantly reduces the effectiveness of conventional phishing detection mechanisms.
The OmegaLord phishing kit follows a more traditional credential-harvesting approach by impersonating a PDF document viewer. Victims are prompted to authenticate using their Microsoft 365 credentials before viewing a document. In addition to usernames and passwords, the phishing page also requests users' phone numbers, providing attackers with additional information that may facilitate MFA interception, account recovery abuse, or targeted social engineering attacks. The details and technicalities of the attack campaign are discussed further below.
Delivery and Infection Chain:
The attack is typically delivered through phishing emails or malicious messages containing links to fake Microsoft authentication pages or counterfeit PDF reader portals. Victims are socially engineered into either entering a legitimate Microsoft device authorization code or providing their Microsoft 365 credentials and phone number. Once the victim completes the authentication process, attackers gain unauthorized access to the Microsoft 365 account and proceed with data theft and further malicious activities.
The infection chain was identified as follows:
Technical Capabilities:
By automatically generating Microsoft OAuth device authorization codes in real time, Jalisco effectively circumvents Microsoft's limited validity window for device codes, demonstrating advanced phishing capabilities. Operators can manage authorized sessions, monitor compromised accounts, and register multiple rogue devices under identities that appear legitimate through the toolkit's dedicated management interface. The exploit significantly reduces the likelihood of detection by conventional credential-based security controls by abusing Microsoft's legitimate authentication infrastructure rather than stealing passwords.
OmegaLord uses a counterfeit PDF reader interface to harvest victims' email addresses, passwords, and mobile phone numbers, combining traditional phishing techniques with advanced information gathering. The additional collection of phone numbers suggests an operational focus on defeating MFA through SIM-based attacks, MFA fatigue campaigns, or targeted account recovery attempts. Following a successful compromise, threat actors enumerate cloud resources, gain access to sensitive SharePoint data, and exfiltrate significant organizational information within minutes before security teams can respond.
Attribution and Evolution:
The Jalisco and OmegaLord phishing kits have not yet been publicly attributed to any specific threat actor. However, rather than relying solely on credential theft, these toolkits demonstrate how phishing attacks continue to evolve by increasingly abusing legitimate authentication mechanisms. Jalisco has joined a growing number of device code phishing frameworks, indicating a broader trend among cybercriminals toward techniques designed to bypass conventional MFA protections and increase the likelihood of account compromise.
Active Campaign and Geographic Spread:
Jalisco and OmegaLord are currently being used in phishing campaigns targeting Microsoft 365 users across multiple industries. Although no specific countries or regions have been identified as primary targets, the widespread adoption of Microsoft 365 makes organizations worldwide vulnerable to these attacks. Organizations that rely heavily on cloud-based collaboration platforms such as Microsoft Entra ID and SharePoint are at greater risk of unauthorized access, data theft, and extortion attempts.
Conclusion:
The emergence of Jalisco and OmegaLord demonstrates the continued evolution of phishing attacks beyond simple credential theft. By exploiting legitimate Microsoft authentication mechanisms and collecting information specifically intended to circumvent MFA protections, these phishing kits significantly increase the likelihood of successful account compromise. Organizations should strengthen identity security by restricting device code authentication where possible, reducing device registration limits, monitoring OAuth application activity, enforcing Conditional Access policies, and educating users about modern phishing techniques that leverage legitimate Microsoft authentication pages.
Successful exploitation can result in unauthorized access to Microsoft 365 accounts, rapid exfiltration of sensitive corporate data, compromise of SharePoint repositories and other cloud resources, unauthorized device registrations, business email compromise (BEC), and extortion attempts involving stolen information. Because attackers can obtain authenticated access without stealing passwords in some cases, traditional credential-based security controls may fail to detect these attacks, increasing the risk of prolonged unauthorized access and significant operational, financial, and reputational damage.
https://reliaquest.com/blog/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge