hacker-news · Crawled Jul 13, 2026

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

1 IoCs
Read original article ↗

AI Summary

A phishing-as-a-service (PhaaS) platform named Forg365 is targeting Microsoft 365 users through sophisticated attack chains involving device code phishing, adversary-in-the-middle (AitM) session theft, and AI-generated lures. The service is offered via Telegram for $400/month and leverages legitimate email services like Amazon SES and SendGrid to evade detection. It enables low-skilled attackers to conduct large-scale phishing operations with post-compromise capabilities such as token vaulting, cookie injection, and AI-assisted email drafting.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain logfriend[[.]]com Details →