Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
ID: c20b9e29-2a91-5097-9697-c2fca013aa95
STIX ID: report--c20b9e29-2a91-5097-9697-c2fca013aa95
Feed Name: The Hacker News
**Forg365** is a subscription-based phishing-as-a-service (PhaaS) platform that targets Microsoft 365 accounts using device-code phishing, adversary-in-the-middle tactics, anti-bot evasion, AI-assisted lure generation, and a Chromium extension (ForgCookie) for persistent access; it distributes via Telegram, abuses legitimate email delivery services (Amazon SES, Twilio SendGrid) to blend into normal traffic, and provides an operator panel for campaign management and post-compromise mailbox monitoring and automation—recommended mitigations include blocking device-code authentication when not required, auditing mailbox artifacts and mail-flow rules, and decommissioning legacy aliases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
