Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
Forg365 Phishing-as-a-Service Platform Uses AI-Generated (TL-2026-1161), also tracked as Forg365 PhaaS, is a high-severity phishing campaign, first published 2026-07-10. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 device-code, maps to 35 MITRE ATT&CK techniques (T1027, T1078.004, T1087.003), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-1161
- Threat ID
- TL-2026-1161
- Also known as
- Forg365 PhaaS, Forg365 phishing kit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all sectors using microsoft 365 entra id, finance, professional services, government administration, health, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in Forg365 Phishing-as-a-Service Platform Uses AI-Generated
Malware and tooling: Forg365 PhaaS kit, ARToken, DEBULL, EvilTokens, Forg365, ForgCookie, Gophish, GraphSpy, Kali365, Sneaky2FA, Tycoon 2FA
Forg365 is a phishing-as-a-service (PhaaS) platform discovered by ZeroBEC that combines adversary-in-the-middle (AiTM) session-cookie proxying and OAuth 2.0 device-code phishing with AI-generated lure content to compromise Microsoft 365 accounts. It ships a browser extension (ForgCookie) for persistent SSO token refresh, an account-intelligence operator dashboard, and antibot/sandbox-evasion protections.
How Forg365 Phishing-as-a-Service Platform Uses AI-Generated works
Forg365 is a subscription-style phishing-as-a-service (PhaaS) kit reported by email-security researchers at ZeroBEC and covered by BleepingComputer on 2026-07-09. It targets Microsoft 365 (Entra ID) accounts through two parallel credential/session-theft paths operated from a single web-based operator panel.
The first path is OAuth 2.0 device-code phishing: victims are shown a Microsoft-branded 'enter this code to verify your device' page and are socially engineered into completing Microsoft's legitimate device-code authentication flow (the flow Microsoft designed for input-constrained devices such as smart TVs and IoT endpoints) against an attacker-registered device/session. Because the victim authenticates through Microsoft's real login surface, the attacker receives valid OAuth access/refresh tokens without ever touching or needing the victim's password, and the flow is largely invisible to classic phishing-page detection since no credential-harvesting form is rendered.
The second path is classic adversary-in-the-middle (AiTM) reverse-proxy phishing: Forg365 transparently proxies the authentication request/response traffic between the victim and genuine Microsoft login infrastructure, relaying MFA challenges in real time and capturing the resulting session cookies as they are issued — defeating password- and OTP-based MFA the same way kits such as Evilginx2, Tycoon 2FA, Sneaky2FA, Mamba 2FA, and Storm-1167's AiTM tooling do.
Once initial tokens/cookies are captured, the operator can install ForgCookie, a browser extension for Chrome, Edge, and Brave, on attacker-controlled or victim-reachable infrastructure. ForgCookie silently triggers repeat OAuth authorization flows using the stolen refresh tokens/session state to mint fresh Microsoft SSO cookies on demand — giving the operator durable, re-authentication-free access to the compromised mailbox and connected M365 services (SharePoint, Teams, OneDrive) well beyond the lifetime of a single stolen session cookie, and materially complicating containment because token/cookie revocation must be paired with app-consent and device-authorization review.
The operator dashboard functions as a full BEC/account-takeover console: campaign creation and phishing-link generation, OAuth application and SMTP-profile configuration for the malicious app registrations used in consent/device-code abuse, stolen-token and session-cookie management, post-compromise operational tracking, an 'account intelligence' view of compromised mailboxes, and keyword-based inbox monitoring (e.g., watching compromised mailboxes for 'invoice', 'wire', 'payment' to identify BEC opportunities). Distinctively, Forg365 integrates an AI content-generation assistant directly into this panel, letting low-skilled operators draft, iterate, and localize convincing lure emails from the same interface used to manage stolen tokens and post-compromise activity — lowering the skill and cost barrier for producing high-quality, targeted phishing lures at scale.
To resist takedown and researcher/sandbox analysis, Forg365's delivery and landing infrastructure uses AES-encrypted redirector chains, bot-detection and debugger-trap logic, sandbox/VM detection checks, VPN detection with redirection of suspected analyst/VPN traffic to benign content, and polymorphic code generation to vary kit fingerprints across deployments. Observed operational infrastructure includes Amazon SES for outbound email delivery, Cloudflare Pages for landing-page hosting, and Gophish for campaign orchestration/tracking.
ZeroBEC noted that many Forg365 capabilities overlap with other prominent PhaaS families targeting Microsoft 365 — including Kali365 and Sneaky2FA — but could not establish an infrastructure or code-sharing link tying Forg365 to those operations; Forg365 is tracked as a distinct, independent PhaaS offering. No CVE applies, as this is an abuse-of-legitimate-functionality (OAuth device-code flow, session-cookie replay) and social-engineering threat rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1161
Defense Evasion
T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion
Privilege Escalation
Discovery
T1087.003 Email Account; T1538 Cloud Service Dashboard
Command and Control
T1090.002 External Proxy; T1102 Web Service
Persistence
T1098.003 Additional Cloud Roles; T1176 Software Extensions
Credential Access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1556.006 Multi-Factor Authentication; T1557 Adversary-in-the-Middle
Collection
T1114 Email Collection; T1530 Data from Cloud Storage
Initial Access
T1199 Trusted Relationship; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service; T1566.004 Spearphishing Voice
Execution
credential-access
T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation
Lateral Movement
T1550.001 Application Access Token
lateral-movement
Resource Development
T1583.006 Web Services; T1584.004 Server; T1585.002 Email Accounts; T1586.002 Email Accounts; T1587.001 Malware
Reconnaissance
T1589 Gather Victim Identity Information; T1598.004 Spearphishing Voice
Impact
stealth
defense-impairment
Affected products and versions in Forg365 Phishing-as-a-Service Platform Uses AI-Generated
- Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 device-code authorization flow)
Vulnerable versions: all tenants with device-code flow enabled - Google — Chrome browser (extension platform abused by ForgCookie)
Vulnerable versions: all - Microsoft — Edge browser (extension platform abused by ForgCookie)
Vulnerable versions: all - Brave Software — Brave browser (extension platform abused by ForgCookie)
Vulnerable versions: all
Remediation for Forg365 Phishing-as-a-Service Platform Uses AI-Generated
Immediate actions
- Restrict or disable Microsoft Entra ID device-code authentication flow tenant-wide unless explicitly required for input-constrained devices
- Enforce Conditional Access policies that block or restrict the device-code and legacy authentication flows
- Monitor Microsoft Entra ID sign-in logs for device-code authentication events, especially from unfamiliar IPs, ASNs, or user agents
- Revoke and refresh all OAuth refresh tokens and session cookies for any account suspected of AiTM or device-code compromise
- Audit and revoke suspicious OAuth application consent grants and app registrations tied to compromised accounts
- Investigate mailbox rules, new inbound-forwarding rules, and new device/session sign-ins on flagged accounts
- Block or alert on installation of unrecognized browser extensions (Chrome/Edge/Brave) capable of silent OAuth token refresh
Workarounds
- Where device-code flow cannot be fully disabled, restrict it via Conditional Access to only trusted named locations/device groups
- Educate users never to enter a device verification code received via an unsolicited email/chat lure, even on legitimate microsoft.com verification pages
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware security keys, certificate-based authentication) that is not susceptible to AiTM session-cookie replay
- Implement continuous access evaluation (CAE) and token binding/Conditional Access token protection in Entra ID to reduce the value of stolen session cookies
- Deploy managed browser extension allow-listing / enterprise browser controls to prevent installation of unauthorized extensions like ForgCookie
- Integrate email-security tooling capable of detecting AI-generated lure content and AiTM proxy redirector chains
- Establish SOC playbooks and detection content specifically for OAuth device-code and AiTM phishing patterns
Timeline of Forg365 Phishing-as-a-Service Platform Uses AI-Generated
- Microsoft documents Storm-2372, a Russian-linked group using OAuth 2.0 device-code phishing against Microsoft 365 targets — the tradecraft later re-emerges in reusable PhaaS platforms such as DEBULL, part of the same device-code-abuse landscape Forg365 belongs to.
- DEBULL, a reusable device-code phishing-as-a-service platform leveraging Storm-2372 tradecraft (with Turkish-language developer markers), is active in a campaign running from late June into early July 2026, using a compromised Croatian rental website as a device-code orchestrator and GraphSpy/ARToken/EvilTokens/Tycoon 2FA for post-exploitation — reported alongside Forg365 as part of the broader M365 device-code phishing kit landscape.
- BleepingComputer's Bill Toulas reports ZeroBEC's direct quote that 'many of the features in Forg365 are present in other infamous PhaaS platforms,' with Sneaky2FA specifically noted for browser-in-the-browser attack tooling.
- Help Net Security (via coverage cited in the same reporting cycle) documents the 'Pink' cyber-extortion group conducting vishing calls that impersonate IT staff to direct victims to a fake Microsoft Entra passkey-enrollment subdomain, delaying victims via scripted social engineering while account takeover for data-theft/extortion purposes occurs — an adjacent device-authentication-abuse technique reported in the same period as Forg365.
- ZeroBEC notes overlap in capability set between Forg365 and other Microsoft 365-focused PhaaS kits (Kali365, Sneaky2FA) but finds no evidence linking their infrastructure or codebases.
- BleepingComputer publishes coverage of the ZeroBEC Forg365 research, making the PhaaS platform's capabilities public.
- Evasion tooling documented: AES-encrypted redirectors, bot detection, debugger traps, sandbox/VM checks, VPN-detection redirection, and polymorphic code.
- AI-assisted lure/email generation feature integrated into the Forg365 operator panel is documented, lowering the skill barrier for producing convincing phishing content.
- ForgCookie browser extension (Chrome/Edge/Brave) identified as a persistence mechanism that silently refreshes stolen Microsoft SSO session cookies via repeated OAuth flows.
- Dual attack-path capability documented: OAuth 2.0 device-code phishing and adversary-in-the-middle (AiTM) session-cookie proxying, both operable from a single Forg365 dashboard.
- ZeroBEC researchers identify and profile the Forg365 phishing-as-a-service platform targeting Microsoft 365 accounts.
Sources cited for Forg365 Phishing-as-a-Service Platform Uses AI-Generated
- New Forg365 phishing platform uses AI to target Microsoft 365 accounts
- Forg365 PhaaS and Fake Passkey Attacks Target Microsoft 365
- CodeStorm Phishing Kit Evolves With Tenant-Aware M365 Replay
- DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation
- DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
- Device Code Phishing: The New AiTM Attack Bypassing MFA
- Evolving Threat: Microsoft AiTM Phishing Attacks
Threats related to Forg365 Phishing-as-a-Service Platform Uses AI-Generated
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions
- Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA
- Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise
Detection coverage for TL-2026-1161
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1161 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.