AI-Powered Phishing Kits Fuel 1,380% Surge in Attacks Targeting Microsoft 365

The surge is linked to AI-powered phishing-as-a-service, or PhaaS. These kits allow even low-skilled criminals to create convincing brand impersonation pages, bypass multi-factor authentication, and steal OAuth tokens.

The findings are part of external threat intelligence from ReliaQuest’s Threat Research team and do not describe a vulnerability in ReliaQuest systems.

Two newly identified tools, named Jalisco and OmegaLord in their respective command-and-control panels, show how phishing operators are redesigning campaigns to account for modern identity defenses.

Rather than only stealing passwords, attackers increasingly target the authentication process itself.

AI Phishing Attacks Surge

Jalisco is a device code phishing toolkit that abuses Microsoft’s legitimate device authorization flow. In a typical attack, victims receive a phishing lure that may appear as a shared document, payment file, or PDF.

The page directs them to enter a device code at a real Microsoft login page. The victim then signs in normally and completes MFA.

However, they are authenticating an attacker-created session. The phishing tool collects the access and refresh tokens issued after authentication, giving the operator access to the Microsoft 365365365 account without learning the victim’s password.

Jalisco uses a newer technique called lure-generation. Older device-code phishing pages included a fixed OAuth code when the page loaded. Those codes expire after roughly 151515 minutes, reducing their usefulness to attackers.

The legitimate Microsoft login window opened by a device code phishing site (Source: reliaquest)
The legitimate Microsoft login window opened by a device code phishing site (Source: reliaquest)

Jalisco instead calls a backend API and generates a fresh code when the victim opens the phishing page. This real-time process defeats the time-to-live protection and improves the likelihood that a target can complete the fraudulent sign-in flow.

The toolkit also includes a web portal that likely helps operators manage stolen sessions at scale.

Attackers can then enroll devices they control in the victim’s Microsoft Entra ID tenant. Such devices receive a Primary Refresh Token, enabling access to persist even after a password reset.

ReliaQuest observed attackers registering more than five devices to a compromised account, often using names such as “microsoft-” or “WINDOWS-” to appear legitimate.

The OmegaLord infostealer pop-up (Source: reliaquest)
The OmegaLord infostealer pop-up (Source: reliaquest)

This persistence method raises the cost of incident response. Defenders must revoke sessions, identify malicious devices, remove each device registration, and investigate access to SharePoint and other SaaS services.

Attackers can exfiltrate sensitive data within as little as six minutes, then use employee data, financial records, or internal documents in extortion attempts.

Jalisco is part of a wider phishing ecosystem that includes EvilTokens, Kali365, Tycoon2fa, Venom, and Darcula. These PhaaS platforms automate infrastructure setup, brand cloning, and phishing-page generation.

Indicators of Compromise

IndicatorTypeAssociated activity
authplanned[.]onlineDomainJalisco device-code phishing kit
grantfundingapplications[.]comDomainJalisco device-code phishing kit

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories