Back to all lessons
Awareness Lessons
3 months ago

Phishing Kits Bypass MFA to Compromise Microsoft 365 Accounts

Attackers have developed sophisticated phishing kits that specifically circumvent multi-factor authentication, long considered a strong defensive baseline. Jalisco abuses the legitimate OAuth 2.0 Device Authorization Grant flow to trick users into granting access to attacker-controlled devices, while OmegaLord harvests credentials and phone numbers by impersonating a PDF reader. These kits demonstrate that MFA alone is not a silver bullet—user awareness and stricter authentication controls are equally critical. The speed of data exfiltration (within minutes of compromise) underscores the need for real-time detection and rapid incident response capabilities.

Tactical Insight

Immediate Actions

  • Train users to recognize OAuth consent phishing prompts and never approve device authorization requests they did not explicitly initiate.
  • Enforce Conditional Access policies in Microsoft 365 to restrict authentication from unmanaged or unrecognized devices.
  • Enable FIDO2/hardware security keys or phishing-resistant MFA (e.g., Windows Hello for Business) as a replacement for SMS or app-based OTP.

Long-Term Improvements

  • Adopt a Zero Trust architecture that continuously validates device health, user identity, and session context before granting resource access.
  • Restrict or disable the OAuth Device Authorization Grant flow for non-essential users via Azure AD Conditional Access or App Registration policies.
  • Implement user entity and behavior analytics (UEBA) to detect anomalous login patterns and rapid data exfiltration events.

Detection Measures

  • Monitor Azure AD sign-in logs and alert on device code authentication attempts originating from unfamiliar locations or IP ranges.
  • Deploy email security gateways with URL sandboxing to identify and block phishing pages masquerading as legitimate PDF readers or Microsoft services.
  • Establish automated playbooks to revoke OAuth tokens and suspend compromised accounts within minutes of a confirmed phishing alert.