
Forg365 PhaaS: Device Code & AitM Attacks on Microsoft 365
In recent months a fresh phishing‑as‑a‑service campaign has emerged, targeting the widely used Microsoft 365 suite. The group behind it, known as Forg365, combines device code phishing with adversary‑in‑the‑middle (AitM) session hijacking, leverages artificial intelligence to craft convincing messages, and includes steps to stay hidden from automated bot defenses.
































































