2 min read

New Microsoft 365 phishing kits now sidestep MFA

ReliaQuest says Jalisco and OmegaLord target Microsoft 365 accounts with device-code phishing and credential theft aimed at bypassing MFA.

Image: BleepingComputer

Two newly identified phishing kits, Jalisco and OmegaLord, are being used to target Microsoft 365 accounts with tactics designed to get around multi-factor authentication. According to ReliaQuest, Jalisco uses device-code phishing, while OmegaLord poses as a PDF reader to steal login credentials and phone numbers that could help attackers intercept or hijack MFA prompts and codes.

The more advanced of the two is Jalisco. It abuses the OAuth 2.0 Device Authorization Grant flow by tricking a victim into approving an attacker-controlled device on Microsoft’s legitimate sign-in page. In a typical attack, the threat actor starts a sign-in request to a Microsoft service, receives a device authorization code, and then uses social engineering to convince the target to enter that code.

Once the victim approves the request, the attacker can access the account without ever collecting the username or password. ReliaQuest says Jalisco generates fresh Microsoft OAuth device codes automatically when a victim opens the phishing page, helping it work around Microsoft’s 15-minute device-code validity window.

Malicious authentication prompt
Malicious authentication prompt

ReliaQuest also says the kit includes a web portal for managing captured sessions and compromised accounts. In some cases, attackers registered five rogue devices on a single account, using names containing “Microsoft” or “Windows” to appear harmless.

After gaining access, attackers search SharePoint and other SaaS services for sensitive data, then move fast.

Recommended reading

ServiceNow RCE flaw is now under active attack

“Threat actors use compromised accounts to access sensitive data, such as customer or employee personally identifiable information (PII), financial records, and internal communications stored in SharePoint and other SaaS platforms.” “Exfiltration typically occurs quickly, in as little as six minutes, before defenders have identified the breach.”

ReliaQuest

OmegaLord is simpler but still effective. It presents a fake PDF Reader login page to steal email addresses, passwords, and phone numbers.

OmegaLord phishing prompt
OmegaLord phishing prompt

ReliaQuest says the focus on phone numbers shows attackers are actively designing campaigns to work around MFA controls. The firm places Jalisco alongside other device-code phishing kits including EvilTokens, Kali365, Tycoon2FA, Venom, and Forg365.

To reduce exposure, ReliaQuest recommends:

  • lowering the Entra ID device-registration limit from 50 to one or two
  • blocking device-code authentication through Microsoft Entra Conditional Access
  • restricting the OAuth Device Authorization grant in Okta
  • auditing and removing unnecessary app registrations
article image
article image
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

// Keep reading