Emerging Microsoft 365 Phishing Kits Bypass MFA Using Device Code Authentication

Summary:

Researchers have identified two advanced phishing toolkits, Jalisco and OmegaLord, actively targeting Microsoft 365 users by exploiting legitimate authentication processes and sophisticated social engineering techniques to bypass multi-factor authentication (MFA). Jalisco abuses the OAuth 2.0 Device Authorization Grant (Device Code Flow) to trick users into authorizing attacker-controlled devices without requiring their passwords, while OmegaLord impersonates a PDF reader to harvest Microsoft 365 credentials and users' phone numbers, potentially facilitating MFA bypass. Once access is obtained, attackers rapidly compromise cloud resources such as SharePoint, exfiltrate sensitive organizational data within minutes, and may subsequently launch extortion campaigns. These evolving phishing techniques highlight the growing shift from traditional credential theft toward the abuse of trusted authentication mechanisms, emphasizing the need for stronger identity security controls, continuous monitoring, and user awareness.

Technical Description:

The Jalisco phishing kit exploits the OAuth 2.0 Device Authorization Grant (Device Code Flow), a legitimate authentication feature designed for devices with limited input capabilities. The toolkit dynamically generates valid Microsoft device authorization codes and presents them to victims through phishing pages. Victims are socially engineered into entering these codes on Microsoft's legitimate authentication portal, unknowingly authorizing an attacker-controlled device. This method completely bypasses password collection and significantly reduces the effectiveness of conventional phishing detection mechanisms.

The OmegaLord phishing kit follows a more traditional credential-harvesting approach by impersonating a PDF document viewer. Victims are prompted to authenticate using their Microsoft 365 credentials before viewing a document. In addition to usernames and passwords, the phishing page also requests users' phone numbers, providing attackers with additional information that may facilitate MFA interception, account recovery abuse, or targeted social engineering attacks. The details and technicalities of the attack campaign are discussed further below.

Delivery and Infection Chain:

The attack is typically delivered through phishing emails or malicious messages containing links to fake Microsoft authentication pages or counterfeit PDF reader portals. Victims are socially engineered into either entering a legitimate Microsoft device authorization code or providing their Microsoft 365 credentials and phone number. Once the victim completes the authentication process, attackers gain unauthorized access to the Microsoft 365 account and proceed with data theft and further malicious activities.

The infection chain was identified as follows:

  • The victim receives a phishing email or malicious message containing a link to a fake Microsoft authentication page or counterfeit PDF reader.
  • The victim is persuaded to authenticate by either entering Microsoft credentials or approving a legitimate Microsoft device authorization code.
  • The phishing kit captures credentials or obtains OAuth device authorization, granting attackers access to the Microsoft 365 account.
  • The attackers register one or more rogue devices or establish authenticated sessions, enabling persistent access while avoiding immediate detection.
  • Sensitive data is rapidly identified and exfiltrated from Microsoft 365 services such as SharePoint, after which the attackers may initiate extortion by threatening to publish the stolen information.

Technical Capabilities:

By automatically generating Microsoft OAuth device authorization codes in real time, Jalisco effectively circumvents Microsoft's limited validity window for device codes, demonstrating advanced phishing capabilities. Operators can manage authorized sessions, monitor compromised accounts, and register multiple rogue devices under identities that appear legitimate through the toolkit's dedicated management interface. The exploit significantly reduces the likelihood of detection by conventional credential-based security controls by abusing Microsoft's legitimate authentication infrastructure rather than stealing passwords.

OmegaLord uses a counterfeit PDF reader interface to harvest victims' email addresses, passwords, and mobile phone numbers, combining traditional phishing techniques with advanced information gathering. The additional collection of phone numbers suggests an operational focus on defeating MFA through SIM-based attacks, MFA fatigue campaigns, or targeted account recovery attempts. Following a successful compromise, threat actors enumerate cloud resources, gain access to sensitive SharePoint data, and exfiltrate significant organizational information within minutes before security teams can respond.

Attribution and Evolution:

The Jalisco and OmegaLord phishing kits have not yet been publicly attributed to any specific threat actor. However, rather than relying solely on credential theft, these toolkits demonstrate how phishing attacks continue to evolve by increasingly abusing legitimate authentication mechanisms. Jalisco has joined a growing number of device code phishing frameworks, indicating a broader trend among cybercriminals toward techniques designed to bypass conventional MFA protections and increase the likelihood of account compromise.

Active Campaign and Geographic Spread:

Jalisco and OmegaLord are currently being used in phishing campaigns targeting Microsoft 365 users across multiple industries. Although no specific countries or regions have been identified as primary targets, the widespread adoption of Microsoft 365 makes organizations worldwide vulnerable to these attacks. Organizations that rely heavily on cloud-based collaboration platforms such as Microsoft Entra ID and SharePoint are at greater risk of unauthorized access, data theft, and extortion attempts.

Conclusion:

The emergence of Jalisco and OmegaLord demonstrates the continued evolution of phishing attacks beyond simple credential theft. By exploiting legitimate Microsoft authentication mechanisms and collecting information specifically intended to circumvent MFA protections, these phishing kits significantly increase the likelihood of successful account compromise. Organizations should strengthen identity security by restricting device code authentication where possible, reducing device registration limits, monitoring OAuth application activity, enforcing Conditional Access policies, and educating users about modern phishing techniques that leverage legitimate Microsoft authentication pages.

Impact:

Successful exploitation can result in unauthorized access to Microsoft 365 accounts, rapid exfiltration of sensitive corporate data, compromise of SharePoint repositories and other cloud resources, unauthorized device registrations, business email compromise (BEC), and extortion attempts involving stolen information. Because attackers can obtain authenticated access without stealing passwords in some cases, traditional credential-based security controls may fail to detect these attacks, increasing the risk of prolonged unauthorized access and significant operational, financial, and reputational damage.

IOC and Context Details:

Topics Details
Tactic Name Initial Access, Credential Access, Defense Evasion, Collection, Exfiltration
Technique Name Phishing, Valid Accounts, OAuth Token Abuse
Sub Technique Name Spearphishing Link, Device Code Authentication Abuse (OAuth 2.0 Device Authorization Grant), Web Portal Credential Phishing
Attack Type Malware
Targeted Applications Microsoft 365, Microsoft Entra ID (Azure AD), SharePoint Online, Microsoft OAuth Authentication Services
Region Impacted Global
Industry Impacted Government, Financial Services, Healthcare, Education, Technology, Manufacturing, and Enterprise organizations
IOC's Domains:
authplanned[.]online
grantfundingapplications[.]com
sessionopen0[.]site
levaquin2us[.]top
nuclear-rose-7ci1cmml-dpoaxo1bhyxi[.]edgeone[.]app
pebr-gl6z-0vzu-434xz[.]b-cdn[.]net
secure-folder-9f8a2983fbf5479e8d8c267e0df4e73d[.]3vvcompany[.]com
116ec3a1ad128d7d[.]darkwebf[.]workers[.]dev

URLs:
hxxps://WINGBOARD[.]b-cdn[.]net/PROOF%20OF%20PAYMENT%2022TH[.]html
hxxps://file[.]kiwi/7ab7c290#z_n5Qh8kwioCUs8jQ6WWhw
CVE NA

Recommended Actions:

  • Disable or restrict OAuth Device Code authentication where it is not required by implementing Microsoft Entra Conditional Access policies.
  • Reduce the Microsoft Entra ID device registration limit from the default value to one or two devices per user to minimize the risk of unauthorized device registrations.
  • Enable Conditional Access policies that enforce strong authentication requirements, device compliance, and location-based access restrictions for Microsoft 365 services.
  • Continuously monitor Microsoft Entra ID logs for suspicious OAuth device authorization requests, newly registered devices, and anomalous sign-in activity.
  • Regularly audit and remove unused or unauthorized OAuth applications and app registrations to reduce the attack surface.
  • Conduct ongoing phishing awareness training to educate users about device code phishing, fake Microsoft login pages, and fraudulent PDF reader prompts requesting credentials or phone numbers.
  • Implement Microsoft Defender for Office 365, or an equivalent email security solution, to detect and block phishing emails, malicious URLs, and credential-harvesting attempts.
  • Establish and regularly test an incident response plan for Microsoft 365 account compromises, including immediate session revocation, device removal, password resets, token revocation, and investigation of potential data exfiltration.

Reference:

https://reliaquest.com/blog/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge

https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/