AI & ML

Forg365: A New Phishing Platform Threatens Microsoft 365 Security

Forg365 is a phishing-as-a-service tool that simplifies Microsoft 365 account takeovers, posing significant challenges for cybersecurity teams.

Jul 14, 2026 3 min read
Sign in to save

A recently uncovered platform called Forg365 is redefining phishing tactics, enabling attackers with minimal technical skills to compromise Microsoft 365 accounts. By leveraging features that automate the evasion of security measures, this tool poses a serious risk to organizations' security frameworks.

Operated via Telegram, Forg365 integrates artificial intelligence to streamline the creation of phishing lures, while employing techniques such as device-code manipulation and adversary-in-the-middle tactics, as outlined by the cybersecurity firm ZeroBEC.

The service offers a five-day free trial to potential users, followed by pricing tiers of $400 per month or an annual fee of $3,800. Users gain access to a centralized operator panel where they can craft phishing lures, oversee email delivery, and manage extracted credential data. Notably, Forg365 provides templates that mimic popular business tools like DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive.

“Phishing-as-a-service has been available for years, but the extent of AI integration in Forg365 is what raises alarms,” remarked Jonathan Ong, a senior analyst at Omdia.

The platform's real concern is how it packages the complete phishing workflow, including crafting lures, bypassing security, and managing compromised accounts, into a subscription-based service, noted cybersecurity researcher Devashri Datta.

Mechanics of Forg365

The phishing campaign analyzed by ZeroBEC often commenced with an email designed around a business document or payment approval context. This correspondence relied on legitimate cloud and email services before ushering the victim through a series of redirects.

Forg365 employs visitor classification to determine whether to present a phishing page involving device-code entry, an adversary-in-the-middle setup, or a dummy page to deflect attention.

When executing the device-code attack, victims are directed to a legitimate Microsoft authentication website, tricked into inputting a code that grants the attacker access to their session. The use of authentic Microsoft infrastructure enhances the credibility of this request.

Additionally, the platform can capture authentication data via adversary-in-the-middle strategies, facilitating session hijacking. ZeroBEC revealed that suspicious visitors are rerouted to benign pages, facilitating the concealment of the phishing flow from security analysts and automated detection systems.

Impact on Incident Response

Forg365 includes a browser extension known as ForgCookie, which allows attackers to generate and refresh single sign-on cookies for Microsoft accounts directly from their browsers, according to ZeroBEC.

It also provides tools to maintain active sessions while monitoring a compromised inbox, where read-only mailbox access can be shared via a protected link.

This makes password resets ineffective in completely terminating an attacker's access, as stolen refresh tokens or ongoing sessions may remain operational even after credential updates. Organizations must also audit devices registered during any breach.

Datta emphasized that Chief Information Security Officers (CISOs) should prioritize the restriction of device-code authentication while implementing strong multi-factor authentication (MFA) protocols such as FIDO2 or WebAuthn passkeys.

For organizations utilizing device-code authentication, it’s wise to block this feature in Microsoft Entra ID, as suggested by Keith Prabhu, CEO of Confidis. Although this strategy would not thwart adversary-in-the-middle attacks or those using stolen session cookies, it could disrupt aspects of Forg365’s methodology.

Companies relying on device-code authentication should ascertain its legitimate applications before imposing a blanket ban, as certain tools may require this access.

Transitioning to phishing-resistant authentication might necessitate additional hardware like security keys, which could lead to increased support requests during the implementation phase. Following any identified breaches, the revocation of active refresh tokens and active session terminations should be standard procedure.

Additionally, incident response teams must assess unauthorized OAuth permissions. Since the ForgCookie extension operates in the attacker's browser, defenders should monitor for unusual sign-in patterns and non-standard Microsoft Graph activities originating from unfamiliar locations, as articulated by ZeroBEC.

Detection efforts must also check for unauthorized changes to mailbox forwarding rules and access privileges that could allow attackers to maintain oversight of communications post-breach. Auditing the registration of new devices and removing any that cannot be attributed to verified users is also essential, as well as investigating whether unauthorized authenticator applications have been enrolled during an incident.

During their investigation, ZeroBEC noted that some registered devices bore names starting with “Forg365,” potentially serving as a valuable indicator for security teams looking to mitigate this emerging threat.

Source: David Brown · www.csoonline.com

Comments

Sign in to join the discussion.