AI‑Powered Phishing‑as‑a‑Service Platform Targets Microsoft 365 Accounts
What Happened — Researchers at ZeroBEC disclosed a new Phishing‑as‑a‑Service (PhaaS) operation named Forg365 that uses adversary‑in‑the‑middle (AiTM) and device‑code techniques, augmented by AI‑generated lures, to steal Microsoft 365 credentials. The service also ships a browser extension that silently refreshes SSO cookies, giving attackers persistent access without re‑authentication.
Why It Matters for Compliance & Audit Readiness
- The campaign illustrates a classic credential‑compromise scenario that SOC 2 CC 6.2 (Logical Access) and CC 7.1 (Security Awareness) are designed to detect, prevent, and evidence.
- AI‑driven lure generation raises the bar for phishing detection, making continuous security‑awareness training and phishing‑simulation programs essential audit evidence.
- Persistent cookie‑stealing extensions bypass traditional MFA controls, highlighting the need for robust session‑monitoring and MFA‑enforcement policies that can be demonstrated during a SOC 2 audit.
Who Is Affected — Enterprises that rely on Microsoft 365 for email, collaboration, and identity (technology, finance, healthcare, education, and any SaaS‑heavy organization).
Recommended Actions
- Verify that MFA is enforced for all Microsoft 365 accounts and that conditional access policies block legacy authentication.
- Deploy a SOC 2‑aligned security‑awareness program that includes AI‑phishing simulations and tracks completion as audit evidence.
- Enable session‑risk monitoring (e.g., Azure AD sign‑in risk) and log all token‑refresh events for continuous control verification.
Source: BleepingComputer – New Forg365 phishing platform uses AI to target Microsoft 365 accounts
Technical Notes — Forg365 combines AiTM, device‑code OAuth abuse, AI‑generated email content, and a “ForgCookie” browser extension that silently refreshes SSO cookies via a silent OAuth flow. Delivery infrastructure leverages Amazon SES and SendGrid for legitimate‑looking email headers.