Code Defence Cyber security

New Jalisco and OmegaLord phishing kits bypass MFA to target Microsoft 365 enterprise accounts

A series of sophisticated credential harvesting campaigns targeting enterprise identity platforms has been uncovered, leveraging newly developed phishing toolkits specifically designed to bypass multi factor authentication. The toolkits manipulate legitimate verification protocols to secure unmonitored command environments directly within corporate clouds.

The threat campaigns utilize the Jalisco and OmegaLord phishing frameworks to target Microsoft 365 environments. Discovered via research tracking records from ReliaQuest, the Jalisco toolkit specifically abuses the OAuth 2.0 Device Authorization Grant flow. By provisioning fresh Microsoft device codes in real-time on malicious landing pages, the toolkit overrides the typical 15-minute validity window. Once a user is tricked into approving the code, the attacker automatically secures active session parameters and cloud token permissions without needing to collect the user password. Concurrently, OmegaLord uses fake PDF applications to collect credentials and intercept push notification codes.

Bypassing multi factor authentication steps removes a core defense boundary from enterprise networks. Once an attacker establishes an authorized token footprint within a cloud directory, they can read internal email communications, modify active document files, download sensitive configuration blueprints, and register persistent backdoor endpoints to maintain access.

– Implement strict conditional access rules to restrict the usage of device code authentication flows across corporate user accounts.

– Transition access policies toward hardware-bound cryptographic multi factor authentication parameters.

– Monitor active user directories for anomalous token creations originating from unrecognized hosting providers or unexpected geographic locations.

– Educate engineering and administrative teams on the mechanics of device code social engineering attempts.

Cloud identity protection relies on the rigorous restriction of unneeded authentication protocols to ensure that public portals do not function as automated initial access channels. #CodeDefence #Microsoft #MFA #Phishing #OAuth #CloudSecurity #IdentityProtection
/

Scroll to Top