Two new phishing kits are hunting Microsoft 365 accounts right now, and both are built to get past multi-factor authentication. Researchers at ReliaQuest named them Jalisco and OmegaLord, and Bleeping Computer has the breakdown. The part that should worry every small business: once one of these kits gets into an account, attackers are searching SharePoint, grabbing your data, and firing off extortion demands in as little as six minutes.
If your business runs on Microsoft 365 (and most do), this one lands close to home.
Why these are worse than normal phishing
Most owners think MFA is the finish line. Turn it on, and phishing stops mattering. These kits are built specifically to break that assumption.
Jalisco uses device-code phishing. It abuses a legitimate Microsoft sign-in feature meant for devices like smart TVs. The attacker starts a real login, Microsoft spits out a short code, and the kit tricks you into typing that code into the genuine Microsoft page. You approve it. Now the attacker’s device is signed into your account, and they never needed your password. Jalisco even generates fresh codes the second you open the fake page, so it beats Microsoft’s own 15-minute expiry window that was added to stop this exact attack.
OmegaLord is more old-school. It poses as a PDF reader login and steals your email, password, and phone number. The phone number is the tell: they want it so they can intercept your text-message MFA codes or trick you into handing one over.
Both get around the MFA you’re relying on. So the fix isn’t “we have MFA, we’re fine.” The fix is the list below.
The checklist
Hand this to whoever runs your IT. It’s ordered by impact.
1. Turn off the device-code sign-in flow in Microsoft 365. This is the single move that kills Jalisco outright. Almost no small business needs device-code authentication. In Entra ID, set a Conditional Access policy that blocks the device code flow for all users. If you have one oddball device that genuinely needs it, allow just that one. Everyone else gets it turned off.
2. Move off text-message and app-tap MFA to phishing-resistant methods. Codes sent by text can be phished and intercepted. That’s exactly what OmegaLord is set up to do. Microsoft just made passkeys the default authentication method in Entra ID (their announcement), and passkeys are the right target. A passkey ties your login to your actual device and can’t be handed to an attacker over the phone. Start with the accounts that matter most: owners, finance, admins.
3. Set up Conditional Access to limit where sign-ins can come from. Block or challenge logins from countries you don’t do business in. Flag sign-ins from brand-new devices. When Jalisco registers a rogue device on an account, this is what catches it, especially since attackers name their fake devices things like “Windows” or “Microsoft” to blend in. If a device you’ve never seen shows up, you want an alert, not silence.
4. Turn on alerts for new device registrations and mass file downloads. These attacks exfiltrate data in about six minutes. You cannot beat six minutes by reviewing logs on Friday. You need automatic alerts the moment a new device joins an account or someone starts pulling large amounts from SharePoint. This is the difference between catching it live and reading about your own breach in a ransom note.
5. Review every device currently registered to your accounts, today. ReliaQuest found cases where attackers had already parked five rogue devices on a single account. Go into Entra ID, pull the list of registered devices per user, and remove anything you can’t account for. If you find a device you don’t recognize, treat that account as compromised: reset the password, revoke active sessions, check for mailbox rules that forward your email out.
6. Tell your team the “type this code into Microsoft” trick is a scam. Your staff will see a message asking them to enter a code on the real Microsoft login page. It looks safe because the page is real. Make it a rule everyone knows: nobody at your company should ever type a login code they didn’t personally request. If a code shows up and you didn’t start a sign-in, it’s an attack.
What we handle for clients
Most of this is configuration, not new software. We set the Conditional Access policies, roll out passkeys, turn off the device-code flow, and wire up the alerts so a real person sees them when something registers a strange device at 2 a.m. That monitoring and response is the core of what we do on the cybersecurity and Microsoft 365 side, because a six-minute attack window means the alert has to reach someone who can act, fast.
If you’re using Microsoft 365 and you’re not sure whether the device-code flow is even turned off, that’s worth ten minutes to check. If any of this is on your radar and you don’t know where you stand, that’s what we’re here for. Book a free 15-minute consult.