Forg365 Phishing‑as‑a‑Service Hijacks Microsoft 365 Sessions with Device‑Code and AitM Tactics
What Happened — A new Phishing‑as‑a‑Service (PhaaS) called Forg365 is selling a turnkey attack chain that abuses Microsoft 365’s device‑code flow and performs adversary‑in‑the‑middle (AitM) session hijacking. The service, advertised on Telegram for $400 /month, combines AI‑generated lures, anti‑bot evasion, and post‑compromise mailbox manipulation to steal credentials and maintain persistent access.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC 6.2 (Logical Access Controls) and CC 7.1 (Security Awareness & Training) – controls designed to prevent credential compromise and to detect anomalous authentication flows.
- Continuous evidence of MFA enforcement, conditional‑access policies, and user‑behavior analytics can serve as audit‑ready proof that the organization mitigates phishing‑derived credential theft.
Who Is Affected — Enterprises and service providers that rely on Microsoft 365 for email, collaboration, and identity management (technology, finance, healthcare, education, etc.).
Recommended Actions
- Enforce MFA and conditional‑access policies that block device‑code grant types for high‑risk users.
- Deploy real‑time security awareness training that includes device‑code phishing simulations.
- Enable Azure AD sign‑in risk detection and log analytics to flag abnormal token exchanges.
- Regularly review privileged mailbox activity for signs of post‑compromise mailbox operations.
Source: The Hacker News
Technical Notes
- Attack vector: Device‑code phishing → AitM session hijack → mailbox takeover.
- Tools: Telegram‑based service marketplace, AI‑generated phishing lures, custom scripts to intercept OAuth device‑code tokens.
- Data at risk: User credentials, email content, calendar data, and any downstream SaaS integrations accessed via the compromised Microsoft 365 session.
Source: The Hacker News