Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.
“Jalisco is a device code phishing toolkit that provisions fresh OAuth codes in real time via a backend API and manages captured sessions through a web portal,” ReliaQuest says. “Its use of lure-generation—a recent evolution that bypasses the 15-minute time-to-live (TTL) on device codes—neutralizes one of the core security assumptions defenders rely on to limit device code phishing. Its presence in the wild signals that lure-generation is highly likely to become a standard feature across a wider range of phishing kits.”
The second tool, dubbed “OmegaLord,” is a credential harvester that also captures phone numbers in order to intercept MFA codes.
“OmegaLord is a newly discovered JavaScript-based credential harvester that goes beyond standard tools by deliberately collecting phone numbers alongside credentials, likely to intercept or hijack MFA—a signal that even traditional credential-theft phishing is being engineered around modern authentication defenses,” the researchers write. “OmegaLord displays a fake PDF reader login page that prompts the user for their email address, password, and phone number. Collecting phone numbers is unusual for credential harvesters and is likely intended to help the attacker intercept or hijack MFA requests during authentication.”
Both of these toolkits indicate that attackers are increasingly interested in automating techniques to bypass MFA.
“Neither tool exists in isolation,” the researchers explain. “Device code phishing tricks users into authenticating on behalf of an attacker, bypassing MFA without exposing credentials, and has surged in 2026—driven by AI-powered PhaaS kits that let any attacker impersonate any brand with minimal skill. Once inside a compromised Microsoft 365 account, attackers establish persistence by pairing multiple attacker-controlled devices to the victim's Entra ID tenant, then move quickly to exfiltrate sensitive data from software-as-a-service (SaaS) platforms for extortion.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.
ReliaQuest has the story: https://reliaquest.com/blog/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge
