CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New phishing kits target Microsoft 365 accounts, evade MFA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2473

As cited

Copy frozen at (site build).

threat intel

New phishing kits target Microsoft 365 accounts, evade MFA

Two phishing kits, Jalisco and OmegaLord, have emerged in active attacks targeting Microsoft 365 accounts with techniques designed to bypass multi-factor authentication (MFA). These tools represent an escalation in phishing sophistication as threat actors work to compromise accounts even when additional authentication layers are in place.

Why it matters: Organizations relying on Microsoft 365 with standard MFA face credential theft risk from these kits; practitioners should investigate whether reverse-proxy phishing or session-hijacking methods are being used and consider additional controls like conditional access policies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New phishing kits target Microsoft 365 accounts, evade MFA

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New phishing kits target Microsoft 365 accounts, evade MFA

Two phishing kits named Jalisco and OmegaLord have been identified in attacks against Microsoft 365 accounts, employing methods designed to bypass multifactor authentication (MFA). The kits represent an evolution in credential theft tactics that circumvent common security controls.

Why it matters: Organizations using Microsoft 365 are at immediate risk; practitioners should review MFA implementation, user training on phishing indicators, and log monitoring for suspicious authentication attempts to detect compromise early.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New phishing kits target Microsoft 365 accounts, evade MFA

Two phishing kits named Jalisco and OmegaLord have been identified in attacks against Microsoft 365 accounts, employing methods designed to bypass multifactor authentication (MFA). The kits represent an evolution in credential theft tactics that circumvent common security controls.

Why it matters: Organizations using Microsoft 365 are at immediate risk; practitioners should review MFA implementation, user training on phishing indicators, and log monitoring for suspicious authentication attempts to detect compromise early.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary