Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts

Forg365 Phishing-as-a-Service Platform Uses AI-Generated (TL-2026-1161), also tracked as Forg365 PhaaS, is a high-severity phishing campaign, first published 2026-07-10. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 device-code, maps to 35 MITRE ATT&CK techniques (T1027, T1078.004, T1087.003), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-1161

Threat ID
TL-2026-1161
Also known as
Forg365 PhaaS, Forg365 phishing kit
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-10
Last reviewed
2026-07-10
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
all sectors using microsoft 365 entra id, finance, professional services, government administration, health, technology
Target regions
Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in Forg365 Phishing-as-a-Service Platform Uses AI-Generated

Malware and tooling: Forg365 PhaaS kit, ARToken, DEBULL, EvilTokens, Forg365, ForgCookie, Gophish, GraphSpy, Kali365, Sneaky2FA, Tycoon 2FA

Forg365 is a phishing-as-a-service (PhaaS) platform discovered by ZeroBEC that combines adversary-in-the-middle (AiTM) session-cookie proxying and OAuth 2.0 device-code phishing with AI-generated lure content to compromise Microsoft 365 accounts. It ships a browser extension (ForgCookie) for persistent SSO token refresh, an account-intelligence operator dashboard, and antibot/sandbox-evasion protections.

How Forg365 Phishing-as-a-Service Platform Uses AI-Generated works

Forg365 is a subscription-style phishing-as-a-service (PhaaS) kit reported by email-security researchers at ZeroBEC and covered by BleepingComputer on 2026-07-09. It targets Microsoft 365 (Entra ID) accounts through two parallel credential/session-theft paths operated from a single web-based operator panel.

The first path is OAuth 2.0 device-code phishing: victims are shown a Microsoft-branded 'enter this code to verify your device' page and are socially engineered into completing Microsoft's legitimate device-code authentication flow (the flow Microsoft designed for input-constrained devices such as smart TVs and IoT endpoints) against an attacker-registered device/session. Because the victim authenticates through Microsoft's real login surface, the attacker receives valid OAuth access/refresh tokens without ever touching or needing the victim's password, and the flow is largely invisible to classic phishing-page detection since no credential-harvesting form is rendered.

The second path is classic adversary-in-the-middle (AiTM) reverse-proxy phishing: Forg365 transparently proxies the authentication request/response traffic between the victim and genuine Microsoft login infrastructure, relaying MFA challenges in real time and capturing the resulting session cookies as they are issued — defeating password- and OTP-based MFA the same way kits such as Evilginx2, Tycoon 2FA, Sneaky2FA, Mamba 2FA, and Storm-1167's AiTM tooling do.

Once initial tokens/cookies are captured, the operator can install ForgCookie, a browser extension for Chrome, Edge, and Brave, on attacker-controlled or victim-reachable infrastructure. ForgCookie silently triggers repeat OAuth authorization flows using the stolen refresh tokens/session state to mint fresh Microsoft SSO cookies on demand — giving the operator durable, re-authentication-free access to the compromised mailbox and connected M365 services (SharePoint, Teams, OneDrive) well beyond the lifetime of a single stolen session cookie, and materially complicating containment because token/cookie revocation must be paired with app-consent and device-authorization review.

The operator dashboard functions as a full BEC/account-takeover console: campaign creation and phishing-link generation, OAuth application and SMTP-profile configuration for the malicious app registrations used in consent/device-code abuse, stolen-token and session-cookie management, post-compromise operational tracking, an 'account intelligence' view of compromised mailboxes, and keyword-based inbox monitoring (e.g., watching compromised mailboxes for 'invoice', 'wire', 'payment' to identify BEC opportunities). Distinctively, Forg365 integrates an AI content-generation assistant directly into this panel, letting low-skilled operators draft, iterate, and localize convincing lure emails from the same interface used to manage stolen tokens and post-compromise activity — lowering the skill and cost barrier for producing high-quality, targeted phishing lures at scale.

To resist takedown and researcher/sandbox analysis, Forg365's delivery and landing infrastructure uses AES-encrypted redirector chains, bot-detection and debugger-trap logic, sandbox/VM detection checks, VPN detection with redirection of suspected analyst/VPN traffic to benign content, and polymorphic code generation to vary kit fingerprints across deployments. Observed operational infrastructure includes Amazon SES for outbound email delivery, Cloudflare Pages for landing-page hosting, and Gophish for campaign orchestration/tracking.

ZeroBEC noted that many Forg365 capabilities overlap with other prominent PhaaS families targeting Microsoft 365 — including Kali365 and Sneaky2FA — but could not establish an infrastructure or code-sharing link tying Forg365 to those operations; Forg365 is tracked as a distinct, independent PhaaS offering. No CVE applies, as this is an abuse-of-legitimate-functionality (OAuth device-code flow, session-cookie replay) and social-engineering threat rather than a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1161

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion

Privilege Escalation

T1078.004 Cloud Accounts

Discovery

T1087.003 Email Account; T1538 Cloud Service Dashboard

Command and Control

T1090.002 External Proxy; T1102 Web Service

Persistence

T1098.003 Additional Cloud Roles; T1176 Software Extensions

Credential Access

T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1556.006 Multi-Factor Authentication; T1557 Adversary-in-the-Middle

Collection

T1114 Email Collection; T1530 Data from Cloud Storage

Initial Access

T1199 Trusted Relationship; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service; T1566.004 Spearphishing Voice

Execution

T1204.001 Malicious Link

credential-access

T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation

Lateral Movement

T1550.001 Application Access Token

lateral-movement

T1550.004 Web Session Cookie

Resource Development

T1583.006 Web Services; T1584.004 Server; T1585.002 Email Accounts; T1586.002 Email Accounts; T1587.001 Malware

Reconnaissance

T1589 Gather Victim Identity Information; T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Forg365 Phishing-as-a-Service Platform Uses AI-Generated

  • Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 device-code authorization flow)
    Vulnerable versions: all tenants with device-code flow enabled
  • Google — Chrome browser (extension platform abused by ForgCookie)
    Vulnerable versions: all
  • Microsoft — Edge browser (extension platform abused by ForgCookie)
    Vulnerable versions: all
  • Brave Software — Brave browser (extension platform abused by ForgCookie)
    Vulnerable versions: all

Remediation for Forg365 Phishing-as-a-Service Platform Uses AI-Generated

Immediate actions

  • Restrict or disable Microsoft Entra ID device-code authentication flow tenant-wide unless explicitly required for input-constrained devices
  • Enforce Conditional Access policies that block or restrict the device-code and legacy authentication flows
  • Monitor Microsoft Entra ID sign-in logs for device-code authentication events, especially from unfamiliar IPs, ASNs, or user agents
  • Revoke and refresh all OAuth refresh tokens and session cookies for any account suspected of AiTM or device-code compromise
  • Audit and revoke suspicious OAuth application consent grants and app registrations tied to compromised accounts
  • Investigate mailbox rules, new inbound-forwarding rules, and new device/session sign-ins on flagged accounts
  • Block or alert on installation of unrecognized browser extensions (Chrome/Edge/Brave) capable of silent OAuth token refresh

Workarounds

  • Where device-code flow cannot be fully disabled, restrict it via Conditional Access to only trusted named locations/device groups
  • Educate users never to enter a device verification code received via an unsolicited email/chat lure, even on legitimate microsoft.com verification pages

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware security keys, certificate-based authentication) that is not susceptible to AiTM session-cookie replay
  • Implement continuous access evaluation (CAE) and token binding/Conditional Access token protection in Entra ID to reduce the value of stolen session cookies
  • Deploy managed browser extension allow-listing / enterprise browser controls to prevent installation of unauthorized extensions like ForgCookie
  • Integrate email-security tooling capable of detecting AI-generated lure content and AiTM proxy redirector chains
  • Establish SOC playbooks and detection content specifically for OAuth device-code and AiTM phishing patterns

Timeline of Forg365 Phishing-as-a-Service Platform Uses AI-Generated

  • Microsoft documents Storm-2372, a Russian-linked group using OAuth 2.0 device-code phishing against Microsoft 365 targets — the tradecraft later re-emerges in reusable PhaaS platforms such as DEBULL, part of the same device-code-abuse landscape Forg365 belongs to.
  • DEBULL, a reusable device-code phishing-as-a-service platform leveraging Storm-2372 tradecraft (with Turkish-language developer markers), is active in a campaign running from late June into early July 2026, using a compromised Croatian rental website as a device-code orchestrator and GraphSpy/ARToken/EvilTokens/Tycoon 2FA for post-exploitation — reported alongside Forg365 as part of the broader M365 device-code phishing kit landscape.
  • BleepingComputer's Bill Toulas reports ZeroBEC's direct quote that 'many of the features in Forg365 are present in other infamous PhaaS platforms,' with Sneaky2FA specifically noted for browser-in-the-browser attack tooling.
  • Help Net Security (via coverage cited in the same reporting cycle) documents the 'Pink' cyber-extortion group conducting vishing calls that impersonate IT staff to direct victims to a fake Microsoft Entra passkey-enrollment subdomain, delaying victims via scripted social engineering while account takeover for data-theft/extortion purposes occurs — an adjacent device-authentication-abuse technique reported in the same period as Forg365.
  • ZeroBEC notes overlap in capability set between Forg365 and other Microsoft 365-focused PhaaS kits (Kali365, Sneaky2FA) but finds no evidence linking their infrastructure or codebases.
  • BleepingComputer publishes coverage of the ZeroBEC Forg365 research, making the PhaaS platform's capabilities public.
  • Evasion tooling documented: AES-encrypted redirectors, bot detection, debugger traps, sandbox/VM checks, VPN-detection redirection, and polymorphic code.
  • AI-assisted lure/email generation feature integrated into the Forg365 operator panel is documented, lowering the skill barrier for producing convincing phishing content.
  • ForgCookie browser extension (Chrome/Edge/Brave) identified as a persistence mechanism that silently refreshes stolen Microsoft SSO session cookies via repeated OAuth flows.
  • Dual attack-path capability documented: OAuth 2.0 device-code phishing and adversary-in-the-middle (AiTM) session-cookie proxying, both operable from a single Forg365 dashboard.
  • ZeroBEC researchers identify and profile the Forg365 phishing-as-a-service platform targeting Microsoft 365 accounts.

Sources cited for Forg365 Phishing-as-a-Service Platform Uses AI-Generated

Threats related to Forg365 Phishing-as-a-Service Platform Uses AI-Generated

Detection coverage for TL-2026-1161

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1161 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats