CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Jalisco Toolkit and AI-Powered Phishing Surge

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2492

As cited

Copy frozen at (site build).

threat intel

The Jalisco Toolkit and AI-Powered Phishing Surge

ReliaQuest identified two phishing toolkits, Jalisco and OmegaLord, actively exploited in campaigns targeting Microsoft 365 environments. Jalisco provisions fresh OAuth codes in real time to defeat time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multi-factor authentication (MFA). The discovery reflects a broader trend of AI-powered phishing-as-a-service (PhaaS) kits lowering the barrier for attackers to conduct sophisticated campaigns that bypass MFA and establish persistence in cloud environments.

Why it matters: Microsoft 365 defenders must immediately review device code authentication settings and disable the feature via Conditional Access policies, since these toolkits enable attackers to compromise accounts and exfiltrate SaaS data for extortion without exposing user credentials or triggering MFA.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

The Jalisco Toolkit and AI-Powered Phishing Surge

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

The Jalisco Toolkit and AI-Powered Phishing Surge

ReliaQuest researchers identified two phishing toolkits, Jalisco and OmegaLord, actively used in Microsoft 365 attacks. Jalisco generates fresh OAuth codes in real time to bypass time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multifactor authentication (MFA). These tools reflect a broader shift toward artificial intelligence (AI)-powered phishing-as-a-service kits that lower barriers for attackers of any skill level to conduct sophisticated campaigns.

Why it matters: Organizations using Microsoft 365 face immediate risk from device code phishing and credential theft that can bypass MFA and establish persistent access; practitioners should disable device code authentication in Entra ID via Conditional Access policies and monitor for device enrollment anomalies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

The Jalisco Toolkit and AI-Powered Phishing Surge

ReliaQuest researchers identified two phishing toolkits, Jalisco and OmegaLord, actively used in Microsoft 365 attacks. Jalisco generates fresh OAuth codes in real time to bypass time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multifactor authentication (MFA). These tools reflect a broader shift toward artificial intelligence (AI)-powered phishing-as-a-service kits that lower barriers for attackers of any skill level to conduct sophisticated campaigns.

Why it matters: Organizations using Microsoft 365 face immediate risk from device code phishing and credential theft that can bypass MFA and establish persistent access; practitioners should disable device code authentication in Entra ID via Conditional Access policies and monitor for device enrollment anomalies.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary