A platform called Forg365 is selling sophisticated phishing tools that use Adversary in the Middle attacks to gain access to Microsoft 365 accounts. Unlike traditional phishing attacks, this method steals session cookies, meaning that changing your password or enabling Multi-Factor Authentication won’t kick the attacker out. Once inside, attackers can monitor your emails for specific keywords, hide Microsoft security warnings from you, or download malicious applications. If attacked, you must manually revoke all sessions in the Microsoft Admin Center.