New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential Harvesting — Threadlinqs Intelligence
As of 2026-07-14, New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential Harvesting is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1306 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Two newly documented phishing kits, Jalisco and OmegaLord, target Microsoft 365, Entra ID, and SharePoint accounts with techniques designed to bypass multi-factor authentication. Jalisco abuses the
ReliaQuest researchers documented two active phishing kits being used against Microsoft 365, Entra ID, and SharePoint tenants: Jalisco and OmegaLord. Jalisco is a device-code phishing toolkit that exploits the OAuth 2.0 Device Authorization Grant flow, a legitimate mechanism intended for input-constrained devices (smart TVs, IoT, CLI tools) that generates a short-lived, human-readable device code a user enters on a Microsoft login page to authorize a session. Attackers initiate the device-code sign-in flow themselves, then use social engineering (fake meeting invites, IT-support pretexts, quishing) to convince a victim to enter the code on the legitimate microsoft.com/devicelogin (or equivalent) page. Because approving the code silently grants the attacker's client an OAuth token, no password or interactive MFA challenge is ever presented to the attacker. Microsoft's mitigation for this abuse pattern is a 15-minute code validity window; Jalisco defeats that control by automatically regenerating fresh device codes on a rolling basis, giving the operator effectively unlimited time to socially engineer a victim into approving a code, and includes an operator-facing web portal for session tracking and account management. OmegaLord takes a different but complementary approach: it presents victims with a spoofed PDF Reader login interface designed to harvest email addresses, passwords, and phone numbers. The explicit collection of phone numbers is notable because it directly targets the credential most commonly used to intercept, redirect, or socially engineer around SMS/voice-based MFA challenges, effectively pairing password theft with a follow-on MFA-interception capability rather than relying on MFA fatigue alone. Once inside a tenant, ReliaQuest observed operators registering multiple rogue devices per compromised account (as many as five), naming them with benign strings containing 'Microsoft' or 'Windows' to blend in with legitimate device inventory, and exfiltrating SharePoint contents, PII, financial records, and internal communications within as little as six minutes of initial compromise -- a window that leaves minimal room for manual SOC triage before data loss occurs. Jalisco and OmegaLord join a broader 2026 wave of OAuth device-code phishing-as-a-service (PhaaS) offerings -- including EvilTokens, Kali365, Tycoon2FA, Venom, and Forg365 -- all of which weaponize the same underlying device-code and adversary-in-the-middle (AitM) session-theft techniques against Microsoft 365/Entra ID identities at scale. A related, broader device-code campaign tracked separately by other researchers (attributed in part to activity clusters Storm-2372, APT29, UTA0304, UTA0307, and UNK_AcademicFlare) compromised 340+ organizations across construction, nonprofit, real estate, manufacturing, financial services, healthcare, legal, and government sectors in the US, Canada, Australia, New Zealand, and Germany, using Railway PaaS-hosted credential-harvesting infrastructure, Cloudflare Workers and Vercel as redirect intermediaries, abused legitimate Cisco/Trend Micro/Mimecast redirect services to bypass spam filters, and residential proxy infrastructure geo-matched to each victim's city to make sign-ins appear normal. Because the technique authorizes a real, unmodified Microsoft login flow, it evades traditional credential-phishing detections that look for spoofed login pages, fake domains, or password-field harvesting, and the resulting OAuth refresh tokens remain valid even after a victim's password is reset, requiring explicit token revocation for remediation.
Weaknesses (CWE)
CWE-287, CWE-290, CWE-451
Target sectors: construction, nonprofit, real-estate, manufacturing, financial-services, health, legal, government administration, enterprise-saas-tenants
Target regions: North America, Europe, Oceania, Middle East, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1584, T1566, T1204, T1098, T1550, T1528, T1621, T1056