Executive Summary
In July 2026, cybersecurity researchers identified two sophisticated phishing kits, Jalisco and OmegaLord, targeting Microsoft 365 accounts. Jalisco employs device-code phishing by generating real-time OAuth device codes, tricking users into authorizing attacker-controlled devices. OmegaLord masquerades as a PDF reader to harvest login credentials and phone numbers, potentially intercepting MFA codes. Both methods effectively bypass multi-factor authentication, granting attackers unauthorized access to sensitive data stored in services like SharePoint and other SaaS platforms. (bleepingcomputer.com)
This incident underscores the evolving nature of phishing attacks, highlighting the need for organizations to reassess and strengthen their authentication mechanisms. The emergence of such advanced phishing kits indicates a trend towards more sophisticated social engineering tactics capable of circumventing traditional security measures.
Why This Matters Now
The discovery of Jalisco and OmegaLord phishing kits demonstrates a significant advancement in cybercriminal tactics, effectively bypassing multi-factor authentication. Organizations must urgently enhance their security protocols to mitigate these evolving threats.
Attack Path Analysis
Attackers employed the Jalisco and OmegaLord phishing kits to compromise Microsoft 365 accounts by bypassing multi-factor authentication (MFA). In the initial compromise, Jalisco utilized device-code phishing to trick victims into authorizing attacker-controlled devices, while OmegaLord masqueraded as a PDF reader to harvest credentials and phone numbers. Following the compromise, attackers escalated privileges by registering multiple rogue devices under seemingly benign names. They then moved laterally within the compromised accounts, accessing sensitive data stored in SharePoint and other SaaS platforms. Command and control were maintained through the attacker-controlled devices, allowing continuous access. Exfiltration occurred rapidly, with data being extracted within minutes. The impact included potential extortion and threats to leak the exfiltrated data.
Kill Chain Progression
Initial Compromise
Description
Attackers used Jalisco's device-code phishing to trick victims into authorizing attacker-controlled devices and OmegaLord's fake PDF reader to harvest credentials and phone numbers.
MITRE ATT&CK® Techniques
Phishing
Multi-Factor Authentication Interception
Multi-Factor Authentication Request Generation
Valid Accounts
Brute Force
Steal Web Session Cookie
Application Layer Protocol
OS Credential Dumping
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.3.6
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Multi-Factor Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Microsoft 365 credential harvesting via Jalisco and OmegaLord phishing kits threatens client financial data access, requiring enhanced MFA controls and OAuth device registration limits.
Health Care / Life Sciences
Device-code phishing targeting Microsoft 365 accounts risks HIPAA-protected patient data exfiltration from SharePoint within minutes, demanding stricter Entra ID authentication policies.
Legal Services
Phishing kits bypassing MFA threaten confidential client communications and case files stored in Microsoft 365, requiring immediate OAuth device authorization restrictions.
Government Administration
Credential harvesting attacks on Microsoft 365 government accounts enable rapid sensitive data exfiltration and potential national security implications through compromised SharePoint access.
Sources
- New phishing kits target Microsoft 365 accounts, evade MFAhttps://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/Verified
- Inside an AI‑enabled device code phishing campaignhttps://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/Verified
- Tycoon2FA hijacks Microsoft 365 accounts via device-code phishinghttps://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it likely limits unauthorized device registration and constrains lateral movement within compromised accounts, thereby reducing the attacker's ability to access sensitive data and exfiltrate it rapidly.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the ability of unauthorized devices to register and gain access, thereby reducing the attacker's initial foothold.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the scope of access for newly registered devices, reducing the attacker's ability to escalate privileges.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit unauthorized lateral movement, reducing the attacker's ability to access sensitive data across platforms.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the attacker's ability to maintain command and control across multiple platforms.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit unauthorized data exfiltration, reducing the attacker's ability to extract sensitive information rapidly.
The CNSF would likely reduce the overall impact by limiting the attacker's ability to access and exfiltrate sensitive data, thereby mitigating potential extortion threats.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- Collaboration Platforms
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive corporate documents, internal communications, and employee personal information stored in Microsoft 365 services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized device registrations.
- • Utilize Multicloud Visibility & Control to monitor and manage device authorizations across cloud services.
- • Apply Egress Security & Policy Enforcement to restrict unauthorized data exfiltration from compromised accounts.
- • Deploy Threat Detection & Anomaly Response to identify and respond to unusual device registration and access patterns.
- • Regularly audit and limit device registration permissions to reduce the risk of unauthorized device authorizations.



