hacker-news · Crawled Jul 13, 2026
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
1 IoCs
Read original article ↗
AI Summary
A phishing-as-a-service (PhaaS) platform named Forg365 is targeting Microsoft 365 users through sophisticated attack chains involving device code phishing, adversary-in-the-middle (AitM) session theft, and AI-generated lures. The service is offered via Telegram for $400/month and leverages legitimate email services like Amazon SES and SendGrid to evade detection. It enables low-skilled attackers to conduct large-scale phishing operations with post-compromise capabilities such as token vaulting, cookie injection, and AI-assisted email drafting.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | logfriend[[.]]com | Details → |