logo

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

ID: c20b9e29-2a91-5097-9697-c2fca013aa95

STIX ID: report--c20b9e29-2a91-5097-9697-c2fca013aa95

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

**Forg365** is a subscription-based phishing-as-a-service (PhaaS) platform that targets Microsoft 365 accounts using device-code phishing, adversary-in-the-middle tactics, anti-bot evasion, AI-assisted lure generation, and a Chromium extension (ForgCookie) for persistent access; it distributes via Telegram, abuses legitimate email delivery services (Amazon SES, Twilio SendGrid) to blend into normal traffic, and provides an operator panel for campaign management and post-compromise mailbox monitoring and automation—recommended mitigations include blocking device-code authentication when not required, auditing mailbox artifacts and mail-flow rules, and decommissioning legacy aliases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.