Cybersecurity researchers have uncovered a new and sophisticated threat actor using a cloud-based phishing-as-a-service (PhaaS) platform, dubbed Forg365, which specifically targets Microsoft 365 users. This malicious operation leverages device code and Active Inventory Management (AitM) session theft to compromise sensitive information.
Forg365 is an intriguing example of how AI-driven security threats are evolving. By using machine learning algorithms, attackers can now rapidly develop and deploy sophisticated malware that bypasses traditional security measures. The platform’s architecture is designed to evade detection by cloud-based security solutions, making it a challenging adversary for defenders. According to reports, Forg365 has been in operation since at least 2025, targeting organizations with Microsoft 365 subscriptions.
At its core, the Forg365 PhaaS platform relies on device code and AitM session theft to gain unauthorized access to sensitive data. Device code is essentially malware that executes arbitrary commands on a target system, allowing attackers to install additional malicious software or steal sensitive information. Meanwhile, AitM sessions are used by attackers to bypass multi-factor authentication (MFA) and assume the identity of legitimate users.
While Forg365’s impact has been significant, researchers emphasize that its operations have largely flown under the radar. The platform’s sophisticated architecture and AI-driven development make it difficult for security solutions to detect and flag as malicious. This raises questions about the evolving threat landscape and the need for more advanced security measures that can keep pace with these emerging threats.
Forg365’s impact extends beyond compromised Microsoft 365 subscriptions, highlighting a broader vulnerability in cloud-based security. As organizations increasingly move their operations to the cloud, the risk of data breaches and unauthorized access grows. The incident serves as a stark reminder of the importance of robust cybersecurity practices, including regular software updates, employee education on phishing tactics, and advanced threat detection measures.
To protect against similar threats, it’s essential for organizations to stay vigilant about software vulnerabilities and implement a layered defense strategy that includes both traditional security solutions and more advanced AI-powered tools. This should involve monitoring network activity in real-time, implementing robust incident response plans, and conducting regular security audits to identify potential weaknesses. By adopting these measures, organizations can reduce their exposure to emerging threats like Forg365 and minimize the risk of data breaches and unauthorized access.
Source: The Hacker News — 2026-07-13