As cited
Copy frozen at (site build).
threat intel
The Jalisco Toolkit and AI-Powered Phishing Surge
ReliaQuest identified two phishing toolkits, Jalisco and OmegaLord, actively exploited in campaigns targeting Microsoft 365 environments. Jalisco provisions fresh OAuth codes in real time to defeat time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multi-factor authentication (MFA). The discovery reflects a broader trend of AI-powered phishing-as-a-service (PhaaS) kits lowering the barrier for attackers to conduct sophisticated campaigns that bypass MFA and establish persistence in cloud environments.
Why it matters: Microsoft 365 defenders must immediately review device code authentication settings and disable the feature via Conditional Access policies, since these toolkits enable attackers to compromise accounts and exfiltrate SaaS data for extortion without exposing user credentials or triggering MFA.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
The Jalisco Toolkit and AI-Powered Phishing Surge
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
The Jalisco Toolkit and AI-Powered Phishing Surge
ReliaQuest researchers identified two phishing toolkits, Jalisco and OmegaLord, actively used in Microsoft 365 attacks. Jalisco generates fresh OAuth codes in real time to bypass time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multifactor authentication (MFA). These tools reflect a broader shift toward artificial intelligence (AI)-powered phishing-as-a-service kits that lower barriers for attackers of any skill level to conduct sophisticated campaigns.
Why it matters: Organizations using Microsoft 365 face immediate risk from device code phishing and credential theft that can bypass MFA and establish persistent access; practitioners should disable device code authentication in Entra ID via Conditional Access policies and monitor for device enrollment anomalies.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
The Jalisco Toolkit and AI-Powered Phishing Surge
ReliaQuest researchers identified two phishing toolkits, Jalisco and OmegaLord, actively used in Microsoft 365 attacks. Jalisco generates fresh OAuth codes in real time to bypass time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multifactor authentication (MFA). These tools reflect a broader shift toward artificial intelligence (AI)-powered phishing-as-a-service kits that lower barriers for attackers of any skill level to conduct sophisticated campaigns.
Why it matters: Organizations using Microsoft 365 face immediate risk from device code phishing and credential theft that can bypass MFA and establish persistent access; practitioners should disable device code authentication in Entra ID via Conditional Access policies and monitor for device enrollment anomalies.
- Source published
- First seen by Cybersecurity Tracker