Jalisco & OmegaLord MFA Bypass: NC SMB Identity Defense

Jalisco and OmegaLord phishing kits bypass Microsoft 365 MFA. Learn how NC businesses stop them with passkeys. Call Preferred Data at (336) 886-3282.

Cover Image for Jalisco & OmegaLord MFA Bypass: NC SMB Identity Defense

TL;DR: Two new phishing kits active in July 2026, Jalisco and OmegaLord, are built to defeat the multi-factor authentication (MFA) protecting Microsoft 365 accounts, and security researchers report they are already in live campaigns. Jalisco abuses a legitimate Microsoft Entra device-registration feature to capture OAuth tokens without ever seeing your password, while OmegaLord harvests usernames, passwords, and phone numbers to intercept one-time codes. Preferred Data Corporation helps North Carolina businesses move to phishing-resistant MFA, harden Entra ID, and monitor identity 24/7 so a stolen code no longer means a stolen company.

Key takeaway: Ordinary one-time-code and push MFA is now routinely bypassed. The durable fix is phishing-resistant MFA (passkeys and FIDO2 hardware keys) plus conditional access and OAuth-grant governance, and Microsoft's move to make passkeys the default in Entra ID this September is the clearest industry signal to act now.

If your business runs on Microsoft 365, your MFA may no longer be the wall you think it is. Contact Preferred Data Corporation at (336) 886-3282 for an identity security assessment. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What are the Jalisco and OmegaLord phishing kits?

Jalisco and OmegaLord are two phishing kits found in active campaigns in July 2026, and both are engineered specifically to bypass the MFA that guards Microsoft 365 accounts. According to BankInfoSecurity, these toolkits harvest Microsoft Entra tokens in real time, meaning the attacker does not need to crack a password or steal a device to walk into an inbox. They represent a maturing market of ready-made kits that put advanced account-takeover techniques in the hands of ordinary criminals.

Jalisco and OmegaLord take different paths to the same goal. Jalisco manipulates a trusted Microsoft feature, while OmegaLord goes after the raw credentials and the phone number needed to grab a one-time code. Both are packaged for scale, which is exactly why small and mid-sized North Carolina businesses, not just large enterprises, are exposed.

How does the Jalisco kit bypass MFA without stealing a password?

Jalisco abuses a legitimate Microsoft Entra device-registration and device-code capability that was designed to let restricted-interface devices, such as printers and smart TVs, sign in. As detailed by ReliaQuest, the kit tricks a victim into authorizing an attacker-controlled device through Microsoft's real login page, so the OAuth token is captured and the attacker gains account access without ever seeing the password.

This is what makes device-code abuse so dangerous. The victim interacts with a genuine Microsoft page, so there is no lookalike domain to spot and no obviously fake form. Because a valid token is issued to the attacker's device, a password reset alone does not necessarily eject them, and traditional password-focused defenses miss the attack entirely. This is why Windows Report describes these kits as advancing attack methods beyond what most businesses are prepared for.

How is OmegaLord different, and why does it want your phone number?

OmegaLord is a credential stealer that harvests usernames, passwords, and phone numbers, and that phone number is the tell. Per reporting from IBTimes, collecting the phone number is likely intended to help intercept the one-time-code (OTP) MFA messages sent to a victim, closing the loop on an account takeover.

The lesson for North Carolina business owners is blunt: SMS and app-based one-time codes are a shared secret that can be phished, relayed, or socially engineered out of a user. Once an attacker has the username, password, and a way to obtain the code, text-message MFA offers far less protection than most teams assume.

Are these attacks connected to a bigger trend?

Yes. Jalisco and OmegaLord are the latest entries in a growing kit ecosystem, following the "EvilTokens" kit that debuted around February 2026 and is widely used for adversary-in-the-middle (AiTM) and business email compromise (BEC) attacks. AiTM works by relaying a login session in real time so the attacker sits invisibly between the user and Microsoft, capturing the authenticated session even when MFA is enabled.

Business email compromise is the payoff. Once inside, attackers read email, learn how the business handles invoices and payments, and then redirect funds or launch further phishing from a trusted internal account. For manufacturers, professional services firms, and healthcare practices across the Piedmont Triad, a single compromised mailbox can expose customers, vendors, and payroll in one move. Preferred Data Corporation's cybersecurity team builds layered defenses so one phished login does not cascade into a full breach.

Not sure whether your Microsoft 365 tenant is hardened against these kits? Call Preferred Data Corporation at (336) 886-3282 for a review.

Why is Microsoft making passkeys the default in Entra ID?

Microsoft has announced that passkeys will become the default authentication method for Entra ID starting September 2026, a direct response to the broader weakness in one-time-code MFA. Passkeys are phishing-resistant by design and cryptographically bound to the domain, which means they will not authenticate to a fake or relayed site the way a typed password or code will.

That domain binding is the whole point. Because a passkey only works on the legitimate Microsoft domain, the AiTM relay and lookalike-page tricks that power these kits simply fail. When the world's largest identity provider changes its default, that is the industry telling every business the era of code-based MFA as a primary defense is ending, and it is time to plan the migration now rather than after an incident.

One-time-code MFA versus phishing-resistant passkeys and FIDO2

The practical difference between legacy MFA and phishing-resistant MFA is stark once you map it against the actual attack techniques these kits use. The table below compares the two approaches across the threats described above.

CapabilityOne-Time-Code / Push MFAPhishing-Resistant Passkey / FIDO2
Stops adversary-in-the-middle (AiTM) relayNo, session can be relayed in real timeYes, credential is bound to the real domain
Stops device-code / OAuth-grant abuse (Jalisco)No, user can be tricked into authorizingStrong, paired with device-code governance
Stops OTP interception (OmegaLord)No, codes can be phished or relayedYes, no shared code to steal
Phishing-resistant by designNoYes
Typical user frictionModerate, retype codes or approve pushesLow, biometric or tap once enrolled
Vulnerable to enrollment vishingYesReduced, but enrollment must be protected

The one caveat in that last row matters. Okta Threat Intelligence reports that voice-phishing (vishing) actors are now targeting the Entra passkey enrollment process itself, calling help desks and users to hijack the moment a passkey is set up. Phishing-resistant MFA is dramatically stronger, but the enrollment and recovery process must be governed just as carefully as the login.

What should a North Carolina business do right now?

The priority is to move high-risk accounts to phishing-resistant MFA, close the device-code and OAuth loopholes, and put a verified process around your help desk. Independent analysis from The Small Business Cybersecurity Guy reinforces that these kits are engineered to defeat the exact controls most SMBs rely on, so incremental tweaks are not enough.

A practical rollout for a Piedmont Triad business looks like this:

  1. Deploy passkeys or FIDO2 hardware keys to executives, finance, IT admins, and anyone with mailbox or payment authority first.
  2. Configure Entra conditional access to require phishing-resistant methods for privileged roles and to block or challenge legacy authentication.
  3. Govern device-code flows and third-party OAuth grants so a printer-style sign-in cannot be weaponized against your tenant.
  4. Establish a strict identity-verification procedure for help-desk requests to resist vishing, especially for passkey enrollment and account recovery.
  5. Turn on 24/7 identity monitoring to catch token theft, impossible-travel sign-ins, and suspicious app consents in real time.

Preferred Data Corporation deploys and manages every layer of this stack. Our managed IT and cybersecurity teams handle the passkey rollout, conditional access design, and OAuth governance, while our network practice hardens the perimeter around your identity platform. We have served North Carolina businesses since 1987, and we build defenses that survive the way attackers actually operate today.

Ready to move past code-based MFA before September? Call Preferred Data Corporation at (336) 886-3282 or reach us here.

Frequently Asked Questions

Can attackers really get into Microsoft 365 without my password?

Yes. The Jalisco kit abuses a legitimate Microsoft Entra device-registration and device-code feature to capture OAuth tokens through Microsoft's real login page, gaining account access without ever seeing your password. This is why password resets alone may not fully evict an attacker who already holds a valid token, and why phishing-resistant MFA and OAuth-grant governance matter so much.

Is text-message or app-based MFA still worth using?

Any MFA is better than none, but one-time-code and push MFA can be bypassed by the AiTM and credential-stealing techniques in these kits. OmegaLord specifically harvests phone numbers to help intercept one-time codes. Treat code-based MFA as a stopgap and prioritize passkeys or FIDO2 hardware keys for high-value accounts.

What makes passkeys "phishing-resistant"?

Passkeys are cryptographically bound to the legitimate domain, so they will not authenticate to a fake or relayed login page. That domain binding defeats the adversary-in-the-middle relay and lookalike-site tactics these kits depend on. Microsoft is making passkeys the default authentication method for Entra ID starting September 2026 for exactly this reason.

Are small and mid-sized NC businesses actually targeted?

Yes. Because these kits are packaged for scale and sold to ordinary criminals, they are pointed at any organization running Microsoft 365, not just large enterprises. Manufacturers, professional services firms, and healthcare practices across High Point, Greensboro, Winston-Salem, and Charlotte are attractive targets because a single compromised mailbox can expose customers, vendors, and payments.

What is vishing and how does it threaten passkeys?

Vishing is voice-phishing, where an attacker calls a user or help desk to socially engineer access. Okta Threat Intelligence reports that vishing actors are now targeting the Entra passkey enrollment process itself, trying to hijack the moment a passkey is set up. This is why enrollment and account recovery need strict, verified procedures even after you adopt passkeys.

How quickly can Preferred Data Corporation deploy phishing-resistant MFA?

We typically begin by protecting your highest-risk accounts (executives, finance, and IT admins) first, then expand across the organization on a managed schedule. The rollout includes passkey and FIDO2 deployment, Entra conditional access, device-code and OAuth governance, and 24/7 identity monitoring. Call (336) 886-3282 to scope a timeline for your business.

Support