Skip to content

Phishing Kits Jalisco and OmegaLord Bypass MFA in Microsoft 365

Bottom Line: New phishing kits bypass Microsoft 365 MFA through token and session capture, enabling persistent access to enterprise accounts.

Two new phishing kits named Jalisco and OmegaLord are being deployed in targeted attacks against Microsoft 365 accounts and employ techniques that overcome multi-factor authentication (MFA).

Security researchers have identified two new phishing kits specifically designed to steal Microsoft 365 credentials and circumvent MFA protections. The Jalisco and OmegaLord kits are already being used in active attack scenarios against enterprise accounts.

The particular risks of these campaigns lie in their functionality: the kits can capture authentication tokens and session information, allowing attackers to gain access even after successfully bypassing MFA. This makes a simple password change insufficient for victims to regain control of their accounts.

For CISOs, this represents elevated risk in the identity security domain. Organizations should intensify user awareness training on phishing detection indicators and review and strengthen additional security layers such as Conditional Access Policies in Microsoft Entra (formerly Azure AD). MFA alone is not sufficient to neutralize such attack vectors.


Source: www.bleepingcomputer.com · Published July 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: