Forg365 is a PhaaS service sold for 400 dollars monthly that combines device-code phishing and AitM attacks against Microsoft 365 and is optimized through antibot evasion and AI-powered lure automation.
An exposed Python HTTP server instance with directory listing enabled revealed an attacker’s phishing toolkit and enabled the discovery of a total of three Evilginx campaigns targeting Microsoft 365.
Threat actors O-UNC-066 use social engineering and a controlled phishing kit to gain access to Microsoft 365 accounts via Entra Passkey enrollment and subsequently conduct data extortion attacks.
Attackers control fake passkey registration pages in real time via PHP panel to bypass multi-factor authentication and gain access to Microsoft 365 accounts.
Forg365 democratizes phishing attacks on Microsoft 365 through an AI-powered service model that combines AiTM techniques with automated lure generation.
Ghost phishing techniques hide malicious pages in encryption until they are decoded in the browser, thereby circumventing traditional email security controls.
Sovereignty must be planned architecturally from the outset, not as a post-migration target, and requires backup infrastructure independent from hyperscaler ecosystems.
German companies neglect implementation of AI security measures while attackers already operate via identities and access paths instead of classic gateway attacks.