Two newly discovered phishing kits, Jalisco and OmegaLord, are actively targeting Microsoft 365 accounts with techniques designed to circumvent multi-factor authentication protections.
Security researchers have identified two sophisticated phishing kits exploiting Microsoft 365 users despite MFA defenses. The kits, named Jalisco and OmegaLord, employ advanced techniques to steal credentials and authentication tokens, rendering traditional MFA protections ineffective.
Both kits operate by creating convincing replicas of Microsoft 365 login pages. When users enter their credentials, the kits capture the information in real time. The critical difference from standard phishing attacks is their ability to intercept and relay MFA challenges, allowing attackers to complete authentication without the victim's knowledge.
Jalisco uses a reverse-proxy approach, positioning itself between the user and Microsoft's servers. This method captures credentials and MFA tokens as they're transmitted, giving attackers legitimate session access. OmegaLord employs similar interception techniques with additional obfuscation to evade detection by security tools.
These kits represent an escalation in phishing sophistication. Traditional MFA—typically SMS codes or authenticator apps—becomes ineffective when attackers control the authentication flow. Users who believe MFA protects them completely remain vulnerable to these attacks.
Organizations using Microsoft 365 should implement additional security measures beyond standard MFA. Recommended protections include conditional access policies that flag unusual login locations or devices, passwordless authentication methods like Windows Hello or FIDO2 security keys, and user education about phishing risks.
Microsoft 365 administrators should review login logs for suspicious activity and consider enforcing stricter authentication requirements for sensitive accounts. Security teams should monitor for phishing domains mimicking Microsoft properties and use threat intelligence to identify Jalisco and OmegaLord indicators of compromise.
The discovery underscores a broader trend: as organizations adopt MFA, attackers develop more sophisticated methods to defeat it. Standard MFA alone is no longer sufficient for comprehensive account protection.
The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring all federal agencies to patch an actively exploited remote code execution vulnerability in Citrix NetScaler appliances by Saturday.
A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.
The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.