Forg365 AI Phishing Platform Targets Microsoft 365 Accounts

A new phishing-as-a-service platform called Forg365 uses AI-generated lures and session theft to compromise Microsoft 365 accounts.

By Central
Forg365 offers cybercriminals a subscription-based toolkit with AI lures and token theft capabilities.
Highlights
  • Forg365 is a phishing-as-a-service platform that combines AI-generated lures with session theft and persistent mailbox access.
  • The platform supports device-code phishing and adversary-in-the-middle attacks to bypass traditional security controls.
  • Organizations should enforce conditional access policies and revoke all sessions after a suspected compromise.

A new phishing-as-a-service (PhaaS) platform named Forg365 is actively targeting Microsoft 365 accounts, offering cybercriminals an all-in-one toolkit that combines AI-generated lures, session theft capabilities, and persistent post-compromise mailbox access. Distributed primarily through Telegram, Forg365 represents a significant escalation in the professionalization of phishing operations, providing malicious actors with a subscription-based model that removes the technical barriers to launching sophisticated attacks against enterprise environments.

What Is Forg365 and How Does the Phishing-as-a-Service Platform Work?

Forg365 is a commercial phishing platform sold on a subscription basis, with options including a 30-day trial, a monthly plan, and an annual plan. This structure allows aspiring attackers, even those with limited technical skill, to deploy advanced phishing campaigns without building infrastructure from the ground up. The platform provides ready-made phishing templates, email sending tools, token storage, and integrated AI capabilities for generating convincing lure messages. Researchers at ZeroBEC identified the platform and documented its features, linking it to a campaign infrastructure hosted in Kyiv, Ukraine, and observing traffic from a Comcast/Xfinity address during device-code phishing activity.

Two Primary Attack Methods: Device-Code Phishing and AiTM Attacks

Forg365 supports two distinct but equally dangerous attack vectors. The first is device-code phishing, where victims are presented with a Microsoft-style verification page and instructed to enter a code. While the Microsoft sign-in page the user interacts with may be legitimate, the code itself grants the attacker access to an attacker-controlled session. This technique can bypass traditional password-focused security controls because the attacker may not need to steal the user’s password directly.

The second method is adversary-in-the-middle (AiTM) phishing. In this scenario, the platform places a phishing page between the victim and Microsoft’s real authentication services. After a successful login, Forg365 captures session information, authentication tokens, and browser cookies. This allows the attacker to maintain access even after the victim has logged out, effectively bypassing the security of the authentication event itself.

AI-Generated Phishing Lures and Anti-Detection Features

A defining feature of Forg365 is its integrated AI tool for generating phishing emails and lures directly within the operator panel. Criminals can create convincing business documents, fake invoices, voicemail notifications, or password reset messages without relying on external AI tools like ChatGPT. This lowers the effort required to craft highly personalized and contextually relevant attacks that are more likely to deceive targets.

The platform also incorporates anti-bot and cloaking features designed to evade security scanners. Researchers observed that Forg365 can redirect traffic originating from VPN networks and security research IPs to harmless decoy websites, effectively hiding its malicious content from automated analysis. This behavior makes it significantly harder for threat intelligence teams to proactively discover and block phishing infrastructure.

Beyond the initial phishing stage, the platform includes a comprehensive feature set for post-compromise operations. A Token Vault stores captured authentication tokens, while Account Intel, mailbox search, keyword monitoring, and viewer links allow attackers to systematically examine compromised inboxes. A browser extension called ForgCookie automatically refreshes Microsoft single sign-on cookies, helping criminals retain long-term, browser-based access after the victim has authenticated.

What Detections Should Security Teams Look For?

Security teams investigating potential Forg365 compromises should focus on specific Microsoft Entra log events. Researchers linked Forg365 activity to device-code sign-in events, Microsoft Authentication Broker activity, unusual Microsoft Graph access patterns, and suspicious new device registrations. Critically, some newly registered devices reportedly used names beginning with “Forg365,” providing a specific and actionable detection clue.

The platform also supports SMTP rotation, campaign scheduling, redirect links, and encrypted SVG files. It offers templates impersonating commonly trusted services such as SharePoint, OneDrive, DocuSign, and Adobe Acrobat Sign, increasing the likelihood of successful credential theft and session hijacking.

How to Protect Microsoft 365 Accounts From Phishing Platforms Like Forg365

Organizations seeking to defend against platforms like Forg365 should implement several key security measures. First, restrict device-code authentication unless it is genuinely required for specific workflows. This simple configuration change can dramatically reduce the attack surface for one of Forg365’s primary attack methods. Second, enforce phishing-resistant multi-factor authentication (MFA) methods, such as FIDO2 security keys or certificate-based authentication, which are far more resilient to AiTM and token theft attacks.

Security teams should also actively monitor Entra ID logs for the indicators described above. After a suspected compromise, simply changing the victim’s password may not be sufficient to evict an attacker. Administrators must revoke all active sessions and refresh tokens to remove the persistent access granted by stolen cookies and tokens. Deploying a reputable endpoint detection and response (EDR) solution with behavioral analysis capabilities can alert on suspicious device registrations and non-interactive session activity.

What Affected Organizations Should Do Now

The emergence of Forg365 confirms that the phishing ecosystem has moved toward commercial, professional-grade services that combine multiple attack techniques into a single, accessible platform. For organizations relying on Microsoft 365, immediate actions include auditing Entra ID logs for device-code sign-ins and unusual device registrations, enforcing conditional access policies that block device-code flows where possible, and training users to recognize that even legitimate-looking verification pages can be part of a sophisticated attack chain. Using a multi-layer endpoint protection solution and a robust password manager with zero-knowledge encryption can further reduce the risk of credential compromise. Organizations should treat any single sign-on token exposure as a critical incident and respond with full session revocation and token rotation.

Share This Article