bleeping-computer · Crawled Jul 9, 2026

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

1 IoCs
Read original article ↗

AI Summary

A new phishing-as-a-service (PhaaS) platform named Forg365 targets Microsoft 365 accounts using AI-generated lures, adversary-in-the-middle (AiTM) phishing, and device-code authentication exploits. The platform provides attackers with a comprehensive dashboard for campaign management, token handling, and persistent access via a browser extension called ForgCookie. It leverages legitimate services like Amazon SES and Cloudflare Pages to blend malicious activity with normal traffic, evading detection while enabling post-compromise persistence through OAuth token and cookie theft.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain sendgrid[.]com Details →