Jalisco and OmegaLord phishing kits target Microsoft 365 accounts and try to bypass MFA

Researchers found two phishing kits that target Microsoft 365 users and are designed to get around multi-factor authentication protections. Jalisco abuses the OAuth 2.0 device authorization flow, also called device-code phishing, by generating fresh Microsoft device codes in real time and registering attacker-controlled devices on victim accounts. OmegaLord uses a fake PDF reader login page to steal Microsoft account credentials and victims’ phone numbers, which can help attackers intercept or hijack MFA challenges and quickly loot SharePoint and other SaaS data.
Why it matters: Organizations using Microsoft 365 should treat this as an active account-takeover risk, especially where device-code sign-ins are allowed. Defenders should review Entra ID device registrations, restrict or block device-code authentication where possible, tighten app registration policies, and warn users not to enter login codes or phone numbers into unsolicited prompts.

Sources

New phishing kits target Microsoft 365 accounts, evade MFA
Bill Toulas 2026.07.14 100% relevant
This article establishes a distinct phishing campaign/tooling story centered on two newly reported kits, Jalisco and OmegaLord, and their Microsoft 365 MFA-evasion methods rather than a single previously tracked kit or law-enforcement action.
← Back to all stories