Hook
More breakout videos from this creator.
A new phishing platform called Forg365 steals your Microsoft 365 password. It keeps stealing your access on auto pilot after you've changed it. How it works. Forg365 is a service, basically a subscription dashboard for running phishing campaigns. Researchers at ZeroBay got access to it. It runs two attack paths against Microsoft accounts. One is device. You're shown a fake Microsoft verification page and talked into like a login, except you're actually authorizing the attacker's through Microsoft's real OAuth flow. The other path is adversary in the middle, and the platform proxies your login in real time and steals your session cookie the moment you authenticate. There's more to the service though. Stealing the cookie isn't the end of it. Forg365 ships a browser extension called Forge Cookie that automatically refreshes the stolen Microsoft session in the background. It requests fresh account data, clears out old cookies, quietly triggers a new login flow to grab your current tokens. The attacker doesn't lose access when they naturally expire. AI is built right into the operator's generating and refining the phishing emails on the same screen used to run the post compromise tools. This isn't just a phishing kit, it's persistent account takeover as a subscription. Made it cheaper and easier to run. Follow for more cyber news.