Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

sessionopen0.site

TLP:CLEAR
Active

Domain

Description

Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge
Pattern Type
STIX
Confidence
75%
Valid From
Jul 15, 2026 16:00
Total Sightings
0
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of sessionopen0.site

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.