Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA).

While Jalisco uses the device-code phishing method, OmegaLord masquerades as a PDF reader to collect account login credentials and associated phone numbers, which could help the attacker intercept or hijack MFA requests or codes.

Both phishing toolkits were analyzed by researchers at cybersecurity firm ReliaQuest, who note that while device-code phishing has become increasingly common, traditional phishing techniques continue to evolve to bypass modern defenses.

The device code phishing technique abuses the OAuth 2.0 Device Authorization Grant flow by tricking victims into authorizing an attacker-controlled device to access their Microsoft account.

The attack typically begins when the threat actor initiates a sign-in request to a Microsoft service, such as Microsoft 365, prompting the platform to generate a device authorization code.