<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb" -->

---
title: New phishing kits target Microsoft 365 accounts, evade MFA
description: Two new phishing kits, Jalisco and OmegaLord, have been discovered targeting Microsoft 365 accounts with MFA-bypassing techniques. Jalisco abuses the OAuth 2.0...
canonical: https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New phishing kits target Microsoft 365 accounts, evade MFA | daily.dev
og:description: Two new phishing kits, Jalisco and OmegaLord, have been discovered targeting Microsoft 365 accounts with MFA-bypassing techniques. Jalisco abuses the OAuth 2.0...
og:url: https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb
og:image: https://api.daily.dev/og/posts/okJl7d0Zb.png
og:image:alt: New phishing kits target Microsoft 365 accounts, evade MFA
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New phishing kits target Microsoft 365 accounts, evade MFA

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

Two new phishing kits, Jalisco and OmegaLord, have been discovered targeting Microsoft 365 accounts with MFA-bypassing techniques. Jalisco abuses the OAuth 2.0 Device Authorization Grant flow, auto-generating fresh device codes in real-time to circumvent Microsoft's 15-minute validity window, while also providing operators a portal to manage compromised sessions. OmegaLord uses a fake PDF Reader login page to harvest email addresses, passwords, and phone numbers to facilitate MFA bypass. After account compromise, attackers exfiltrate data from SharePoint and SaaS platforms in as little as six minutes before launching extortion demands. ReliaQuest, which analyzed both kits, recommends reducing Entra ID device-registration limits, blocking device code authentication via Conditional Access, and restricting OAuth Device Authorization grants in Okta.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa>

## Questions this post answers

### How does the Jalisco phishing kit bypass Microsoft's device code expiration to hijack Microsoft 365 accounts?

Jalisco abuses the OAuth 2.0 Device Authorization Grant flow by generating a fresh Microsoft device authorization code in real time whenever a victim opens the phishing page, which sidesteps Microsoft's 15-minute code validity window designed to stop device-code phishing. Once a victim enters the code on the legitimate Microsoft login page, the attacker gains account access without needing a username or password.

_Teams hardening Microsoft 365 against MFA bypass techniques can follow security coverage like this on daily.dev._

### What should I do to stop device code phishing attacks against Microsoft Entra ID accounts?

Reduce the Entra ID device-registration limit from its default of 50 down to one or two, which also speeds up remediation if an account is hijacked. Additionally, block device code authentication through Microsoft Entra Conditional Access, restrict the OAuth Device Authorization grant in Okta, and audit and remove unnecessary app registrations.

_Admins tightening Entra ID defenses against device-code phishing can track fixes like these on daily.dev._

### What is the OmegaLord phishing kit and how does it target Microsoft 365 users?

OmegaLord is a phishing tool that uses a fake PDF Reader login page to steal email addresses, passwords, and phone numbers from Microsoft 365 users. Collecting phone numbers is intended to help attackers intercept or hijack MFA requests or codes, directly engineering around multi-factor authentication as a security control.

_Anyone tracking new MFA-bypass phishing tactics can follow security news like this on daily.dev._

## Similar posts on daily.dev

- [New phishing campaign tricks employees into bypassing Microsoft 365 MFA](https://daily.dev/posts/new-phishing-campaign-tricks-employees-into-bypassing-microsoft-365-mfa-2reed6azp) · CSO Online · 0 upvotes · 0 comments
- [Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing](https://daily.dev/posts/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing-zzaraji3g) · BleepingComputer · 1 upvotes · 1 comments

---

Tags: [#microsoft](https://daily.dev/tags/microsoft), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New phishing kits target Microsoft 365 accounts, evade MFA","url":"https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb"},"datePublished":"2026-07-14T12:50:32.351Z","dateModified":"2026-09-14T07:37:34.417Z","description":"Two new phishing kits, Jalisco and OmegaLord, have been discovered targeting Microsoft 365 accounts with MFA-bypassing techniques. Jalisco abuses the OAuth 2.0...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/eb1ae6750ace35ac7ea74e505630ab56?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/eb1ae6750ace35ac7ea74e505630ab56?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"microsoft,authentication,phishing,oauth","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"New phishing kits target Microsoft 365 accounts, evade MFA"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb#faq","mainEntity":[{"@type":"Question","name":"How does the Jalisco phishing kit bypass Microsoft's device code expiration to hijack Microsoft 365 accounts?","acceptedAnswer":{"@type":"Answer","text":"Jalisco abuses the OAuth 2.0 Device Authorization Grant flow by generating a fresh Microsoft device authorization code in real time whenever a victim opens the phishing page, which sidesteps Microsoft's 15-minute code validity window designed to stop device-code phishing. Once a victim enters the code on the legitimate Microsoft login page, the attacker gains account access without needing a username or password. Teams hardening Microsoft 365 against MFA bypass techniques can follow security coverage like this on daily.dev."}},{"@type":"Question","name":"What should I do to stop device code phishing attacks against Microsoft Entra ID accounts?","acceptedAnswer":{"@type":"Answer","text":"Reduce the Entra ID device-registration limit from its default of 50 down to one or two, which also speeds up remediation if an account is hijacked. Additionally, block device code authentication through Microsoft Entra Conditional Access, restrict the OAuth Device Authorization grant in Okta, and audit and remove unnecessary app registrations. Admins tightening Entra ID defenses against device-code phishing can track fixes like these on daily.dev."}},{"@type":"Question","name":"What is the OmegaLord phishing kit and how does it target Microsoft 365 users?","acceptedAnswer":{"@type":"Answer","text":"OmegaLord is a phishing tool that uses a fake PDF Reader login page to steal email addresses, passwords, and phone numbers from Microsoft 365 users. Collecting phone numbers is intended to help attackers intercept or hijack MFA requests or codes, directly engineering around multi-factor authentication as a security control. Anyone tracking new MFA-bypass phishing tactics can follow security news like this on daily.dev."}}]}
```

