New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

KnowBe4 Team | Jul 23, 2026

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

“Jalisco is a device code phishing toolkit that provisions fresh OAuth codes in real time via a backend API and manages captured sessions through a web portal,” ReliaQuest says. “Its use of lure-generation—a recent evolution that bypasses the 15-minute time-to-live (TTL) on device codes—neutralizes one of the core security assumptions defenders rely on to limit device code phishing. Its presence in the wild signals that lure-generation is highly likely to become a standard feature across a wider range of phishing kits.”

The second tool, dubbed “OmegaLord,” is a credential harvester that also captures phone numbers in order to intercept MFA codes.

“OmegaLord is a newly discovered JavaScript-based credential harvester that goes beyond standard tools by deliberately collecting phone numbers alongside credentials, likely to intercept or hijack MFA—a signal that even traditional credential-theft phishing is being engineered around modern authentication defenses,” the researchers write. “OmegaLord displays a fake PDF reader login page that prompts the user for their email address, password, and phone number. Collecting phone numbers is unusual for credential harvesters and is likely intended to help the attacker intercept or hijack MFA requests during authentication.”

Both of these toolkits indicate that attackers are increasingly interested in automating techniques to bypass MFA.

“Neither tool exists in isolation,” the researchers explain. “Device code phishing tricks users into authenticating on behalf of an attacker, bypassing MFA without exposing credentials, and has surged in 2026—driven by AI-powered PhaaS kits that let any attacker impersonate any brand with minimal skill. Once inside a compromised Microsoft 365 account, attackers establish persistence by pairing multiple attacker-controlled devices to the victim's Entra ID tenant, then move quickly to exfiltrate sensitive data from software-as-a-service (SaaS) platforms for extortion.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

ReliaQuest has the story: https://reliaquest.com/blog/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.