๐จ ZeroBEC discovered Forg365, a Telegram-distributed Microsoft 365 PhaaS built for account takeover.
This is not just a phishing page.
Forg365 packages:
๐จ lure delivery
๐ device-auth abuse
๐ญ Sneaky 2FA-style AiTM
๐ค AI lure generation
๐ช browser-session refresh
๐ฌ mailbox ops after compromise
The full research:
https://t.co/YGqKvdORd5
Endpoint security did not stop evolving at antivirus.
AV remained an essential prevention layer, but the industry recognized that prevention alone could not detect every threat. Security teams needed visibility into what happened after access, correlation across activity, and the ability to contain malicious behavior.
Why should email security stop at the gateway?
Secure email gateways remain important. But modern BEC is increasingly constructed from components that appear technically legitimate:
โ๏ธ A real Gmail or Microsoft 365 account
โ An authenticated but compromised vendor
โ๏ธ A trusted cloud or delivery service
๐ A genuine Microsoft authorization workflow
๐ณ A financial request with no malicious link or attachment
The attack may not be visible in any single email artifact. It becomes visible when the message is evaluated against the recipient, the relationship, the requested business action, and the mailbox and identity activity that follows delivery.
Our new CISO guide examines:
โข Four real attacks that looked reasonable to the control in front of them
โข Why legitimate infrastructure has become part of the attack path
โข The security layer required beyond the SEG
โข Six capabilities CISOs should demand from behavioral email security
The question is no longer simply, โDid the message pass authentication?โ
It is: โDoes this communication make sense for this recipient, this relationship, and this business process?โ
Read the ZeroBEC CISO guide:
https://t.co/f4skI5sB5L
#EmailSecurity #BEC #CISO #Cybersecurity
๐จ Greatness PhaaS is evolving.
Following the prevention of a phishing campaign targeting one of our financial-sector customers, we traced the infrastructure behind the attack and uncovered a modern deployment of Greatness PhaaS combining AiTM and Microsoft Device Code phishing.
Our investigation also found:
๐น RingCentral-themed phishing lures
๐น Low-cost subscriptions lowering the barrier to entry
๐น Shared licensing & infrastructure across operators
๐น Recipient exclusion capabilities
๐น Rich operational features that make the platform accessible to less sophisticated threat actors
Despite being one of the more capable phishing platforms, there has been relatively little public research on how Greatness has evolved in recent years.
Read our full technical analysis, IOCs, and detection guidance:
๐ https://t.co/kQCqapZet4
#CyberSecurity #ThreatResearch #ThreatIntel #Phishing #AiTM #DeviceCode #Microsoft365 #Greatness #BEC #ZeroBEC
๐จ New ZeroBEC research: Operation BlueDash
We traced a workplace phishing campaign from fake Microsoft Teams and Zoom updates through malicious installers, compromised infrastructure, and the deployment of multiple legitimate RMM tools, including Level RMM, ScreenConnect, and Tactical RMM.
Our investigation also uncovered the operatorsโ GitHub repositories, commit history, evolving payload delivery methods, and hands-on reconnaissance performed on compromised endpoints.
Excellent research by @BhalgamaVedant ๐
๐ https://t.co/BGiHegiMvj
#ThreatResearch #Phishing #RMM #Cybersecurity #MicrosoftTeams #ScreenConnect #ZeroBEC
๐จ ZeroBEC caught another Kali365 phishing attempt.
A fake delivery notification led to a counterfeit Microsoft 365 quarantine page, then abused the legitimate device-code flow to authorize an attacker-controlled session.
IOCs:
hxxps://pkecm[.]com/detailings/
hxxps://35ad13zh43[.]designsthattrust[.]de/l/I82OUJPbyJQ
hxxps://35ad13zh43[.]designsthattrust[.]de/api/status/389
Never enter a device code supplied by email. #Phishing #Microsoft365
๐ ZeroBEC is now available on Microsoft Marketplace.
Protect Microsoft 365 against BEC, credential phishing, AiTM, device-code abuse, and QR-code attacks, with no MX changes and deployment in under 60 minutes.
Explore ZeroBEC:
https://t.co/27wfnU1G2J
#ZeroBEC#Microsoft365 #EmailSecurity #Cybersecurity
๐ก๏ธ ZeroBEC prevented an active JIVS PhishKit campaign targeting multiple users at one of our customers after the emails bypassed traditional security controls and landed directly in inboxes.
Our investigation traced the attack to a reusable, domain-adaptive credential harvester active since 2025. The kit automatically impersonates the victimโs organization, uses anti-debugging controls, captures multiple password attempts, and redirects the victim back to their legitimate corporate domain.
๐ Full technical analysis:
https://t.co/F9syWl8Uxv
#ZeroBEC #Phishing #EmailSecurity #ThreatResearch #CredentialTheft
๐จ New ZeroBEC research
We identified and prevented a Microsoft 365 device-code phishing campaign that did not use a fake Microsoft login page.
Instead, users were pushed into the legitimate Microsoft device login flow while a backend broker generated and polled Microsoft Authentication Broker tokens.
Our investigation exposed DEBULL, a reusable PhaaS framework with:
๐น Storm-2372-style tradecraft
๐น Cloudflare Workers deployment
๐น reusable lure templates
๐น Microsoft Authentication Broker abuse
๐น GraphSpy-like post-authentication activity
๐น Telegram, chat, voice, and file-transfer components
๐น Turkish code-lineage markers
The same IP that served the DEBULL panel also created the attacker-side Microsoft Authentication Broker session.
Full research:
https://t.co/6wT7uj5Ri2
#ThreatResearch #Microsoft365 #EntraID #Phishing #GraphSpy #ZeroBEC
๐จ New ZeroBEC Research: Sneaky 2FA Returns
This campaign went far beyond a fake Microsoft login page.
We observed a compromised trusted SaaS sender account used to target enterprise IT users with a Microsoft security alert lure, wrapped inside a business-thread chain.
The phishing flow then moved through redirect layers into a Sneaky 2FA-style kit that showed clear evolution:
๐ Identity-check gating
๐งฌ Session-mutated routes and loaders
๐ชช Tenant-branded Microsoft 365 rendering
๐ Live Microsoft Entra credential replay
๐ฒ MFA collection paths
๐ Cross-stage signals across email, browser, and identity telemetry
The key lesson: static sender reputation, static URL reputation, and SEG-only detection are not enough when trust is abused across the full chain.
Read the full research:
https://t.co/P1EdKFSRhY
#Sneaky2FA #Microsoft365 #BEC #ATO #EmailSecurity #Phishing #IdentitySecurity #ThreatResearch
Introducing Nyasher, a live Google account takeover framework uncovered by ZeroBEC.
Active since at least Dec 2025, Nyasher blends Gmail forwarding, Webflow, Cloudflare Workers, blob-hosted Google sign-in, WebSockets, hidden admin telemetry, and Google Drive handoff.
Full analysis:
https://t.co/ULFyLEVW6J
#ZeroBEC #Nyasher #Phishing #BEC #AccountTakeover #GoogleWorkspace #ThreatResearch #CyberSecurity
New ZeroBEC research by @BhalgamaVedant is live.
We analyzed a China-nexus spear-phishing campaign targeting India Income Tax recipients and delivering AsyncRAT.
The blog covers the lure, infection flow, payload behavior, infrastructure, and IOCs.
Read the full analysis:
https://t.co/zzrPbBOkhx
#ZeroBEC #ThreatResearch #AsyncRAT #Phishing #EmailSecurity #Malware #CyberSecurity
New ZeroBEC research: GPPStorm
A phishing campaign using fake Google Partner invitations to target Workspace credentials.
The lure looks positive, not suspicious:
โYour agency was selected.โ
Behind it:
cloud mail abuse, redirectors, typosquats, Netlify iframes, fake Google sign-in.
https://t.co/Sr8jLUTDwX
#GPPStorm #EmailSecurity #Phishing #GoogleWorkspace #BEC
๐จ We uncovered a phishing campaign using fake ITR refund lures to deliver LX RAT via a heavily obfuscated AutoIt loader.
Our latest blog analyzes the full attack chain and how @Z3r0b3c blocked the threat.
๐ Details below.
https://t.co/eoJrTb26YJ
#phishing#threatintel#LXRAT
๐จ New ZeroBEC research: LX RAT is now appearing in a highly active ITR refund phishing campaign.
The chain: phishing email โ compromised redirector โ Dropbox ZIP โ AutoIt loader โ sandbox evasion โ persistence โ LX RAT.
Multiple leading SEGs were evaded.
Research with @BhalgamaVedant .
Full writeup: https://t.co/mbZHn9bhvP
#EmailSecurity #ThreatIntel #Phishing #LXrat #MalwareResearch