HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

AI‑Powered Phishing‑as‑a‑Service Platform Targets Microsoft 365 Accounts

ZeroBEC reports Forg365, a new AI‑driven Phishing‑as‑a‑Service that harvests Microsoft 365 credentials via device‑code and AiTM techniques, then uses a browser extension to maintain persistent access. The tactic underscores the need for SOC 2‑aligned access controls and security‑awareness evidence.

LiveThreat™ Intelligence · 📅 July 09, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

AI‑Powered Phishing‑as‑a‑Service Platform Targets Microsoft 365 Accounts

What Happened — Researchers at ZeroBEC disclosed a new Phishing‑as‑a‑Service (PhaaS) operation named Forg365 that uses adversary‑in‑the‑middle (AiTM) and device‑code techniques, augmented by AI‑generated lures, to steal Microsoft 365 credentials. The service also ships a browser extension that silently refreshes SSO cookies, giving attackers persistent access without re‑authentication.

Why It Matters for Compliance & Audit Readiness

  • The campaign illustrates a classic credential‑compromise scenario that SOC 2 CC 6.2 (Logical Access) and CC 7.1 (Security Awareness) are designed to detect, prevent, and evidence.
  • AI‑driven lure generation raises the bar for phishing detection, making continuous security‑awareness training and phishing‑simulation programs essential audit evidence.
  • Persistent cookie‑stealing extensions bypass traditional MFA controls, highlighting the need for robust session‑monitoring and MFA‑enforcement policies that can be demonstrated during a SOC 2 audit.

Who Is Affected — Enterprises that rely on Microsoft 365 for email, collaboration, and identity (technology, finance, healthcare, education, and any SaaS‑heavy organization).

Recommended Actions

  • Verify that MFA is enforced for all Microsoft 365 accounts and that conditional access policies block legacy authentication.
  • Deploy a SOC 2‑aligned security‑awareness program that includes AI‑phishing simulations and tracks completion as audit evidence.
  • Enable session‑risk monitoring (e.g., Azure AD sign‑in risk) and log all token‑refresh events for continuous control verification.

Source: BleepingComputer – New Forg365 phishing platform uses AI to target Microsoft 365 accounts

Technical Notes — Forg365 combines AiTM, device‑code OAuth abuse, AI‑generated email content, and a “ForgCookie” browser extension that silently refreshes SSO cookies via a silent OAuth flow. Delivery infrastructure leverages Amazon SES and SendGrid for legitimate‑looking email headers.

📰 Original Source
https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →