As cited
Copy frozen at (site build).
threat intel
New phishing kits target Microsoft 365 accounts, evade MFA
Two phishing kits, Jalisco and OmegaLord, have emerged in active attacks targeting Microsoft 365 accounts with techniques designed to bypass multi-factor authentication (MFA). These tools represent an escalation in phishing sophistication as threat actors work to compromise accounts even when additional authentication layers are in place.
Why it matters: Organizations relying on Microsoft 365 with standard MFA face credential theft risk from these kits; practitioners should investigate whether reverse-proxy phishing or session-hijacking methods are being used and consider additional controls like conditional access policies.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
New phishing kits target Microsoft 365 accounts, evade MFA
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
New phishing kits target Microsoft 365 accounts, evade MFA
Two phishing kits named Jalisco and OmegaLord have been identified in attacks against Microsoft 365 accounts, employing methods designed to bypass multifactor authentication (MFA). The kits represent an evolution in credential theft tactics that circumvent common security controls.
Why it matters: Organizations using Microsoft 365 are at immediate risk; practitioners should review MFA implementation, user training on phishing indicators, and log monitoring for suspicious authentication attempts to detect compromise early.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
New phishing kits target Microsoft 365 accounts, evade MFA
Two phishing kits named Jalisco and OmegaLord have been identified in attacks against Microsoft 365 accounts, employing methods designed to bypass multifactor authentication (MFA). The kits represent an evolution in credential theft tactics that circumvent common security controls.
Why it matters: Organizations using Microsoft 365 are at immediate risk; practitioners should review MFA implementation, user training on phishing indicators, and log monitoring for suspicious authentication attempts to detect compromise early.
- Source published
- First seen by Cybersecurity Tracker