Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
Summary
Hide ▲
Show ▼
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox abuse. The ecosystem packages lure creation, delivery, evasion, token handling, and post-compromise tooling for low-skill affiliates at industrial scale.
Related Happenings
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Triad Nexus investment scam and brand impersonation campaign targeting emerging markets
Campaign
H score33
First: 14.04.2026 15:00
Last: 14.04.2026 15:00
Sources 1
About this happening:
The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...
Triad Nexus investment scam and brand impersonation campaign targeting emerging markets
CampaignAbout this happening: The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...
Triad Nexus expands fraud ecosystem and shifts into emerging markets after 2025 US sanctions
Threat Actor Meta
H score43
First: 14.04.2026 15:00
Last: 14.04.2026 15:00
Sources 1
About this happening:
Triad Nexus expanded its fraud ecosystem after US Treasury sanctions in 2025, increasing operational scale and shifting into emerging markets. The network’s use of U...
Triad Nexus expands fraud ecosystem and shifts into emerging markets after 2025 US sanctions
Threat Actor MetaAbout this happening: Triad Nexus expanded its fraud ecosystem after US Treasury sanctions in 2025, increasing operational scale and shifting into emerging markets. The network’s use of U...
Timeline
-
13.07.2026 16:03 2 articles · 13d ago
Forg365 targets Microsoft 365 accounts with device code phishing and AitM session theft
Initial DisclosureForg365 is a subscription-based phishing-as-a-service platform that targets Microsoft 365 accounts with device code phishing, adversary-in-the-middle (AitM) session theft, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations. The kit is distributed via Telegram for $400 a month or $3,800 per year, uses legitimate delivery infrastructure such as Amazon SES and Twilio SendGrid, exposes an operator panel at logfriend[.]com/login, and includes the ForgCookie browser extension for continued access to compromised accounts.
Show sources
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft — thehackernews.com — 13.07.2026 16:03
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft — thehackernews.com — 13.07.2026 16:03