Forg365 targets Microsoft 365 with device code and AitM phishing, then uses stolen tokens for persistent browser sessions and mailbox access.

Forg365 targets Microsoft 365 with device code and AitM phishing, then uses stolen tokens for persistent browser sessions and mailbox access.

The Telegram-distributed service combines AI-assisted lures with device-code phishing and attacker-side session refresh, complicating containment after an account is breached.