Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions — Threadlinqs Intelligence
As of 2026-07-11, Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions is a high-severity phishing threat attributed to Forg365 operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1202 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Forg365 operators · FINANCIAL
Forg365 is a commercial phishing-as-a-service (PhaaS) platform distributed via Telegram ($400/month, $3,800/year) that steals Microsoft 365/Entra ID session tokens and cookies through two attack
Forg365 is a subscription-based phishing-as-a-service (PhaaS) operation, first documented by researchers at ZeroBEC and subsequently reported by Cybersecurity News, BleepingComputer, CyberPress, GBHackers, and Windows Report in July 2026, that specifically targets Microsoft 365 and Entra ID (Azure AD) accounts. The platform is sold entirely through Telegram with a five-day free trial, $400/month, or $3,800/year subscription tiers, and provides a full operator dashboard for campaign management, OAuth application/SMTP configuration, token and cookie management, and AI-assisted phishing-email generation.
Forg365 supports two primary attack chains. The first, and the one researchers describe as the trending technique, abuses Microsoft's legitimate OAuth 2.0 device-code authentication flow (designed for input-constrained devices such as smart TVs and IoT appliances): victims are shown a Microsoft-styled verification-code page and are guided through the genuine Microsoft sign-in/device-authorization surface, unknowingly authorizing an attacker-controlled device/session. Because the victim interacts with authentic Microsoft infrastructure and never enters a password into a fake page, this bypasses many classic anti-phishing controls and does not require credential capture at all — Entra logs the event as `originalTransferMethod=deviceCodeFlow` with an attacker-registered device typically named with a "Forg365-" prefix.
The second attack path is a classical adversary-in-the-middle (AiTM) reverse-proxy phishing flow: Forg365 sits between the victim and Microsoft's real authentication endpoints, relaying credentials and MFA challenges in real time and capturing the resulting session cookies, access tokens, and refresh tokens — defeating password-based MFA that does not bind sessions to a client (i.e., non-phishing-resistant MFA).
Persistence is provided by ForgCookie, a companion browser extension compatible with Chrome, Edge, and Brave. ForgCookie requests account data from the Forg365 backend, clears the victim's existing Microsoft SSO session cookies, and triggers a silent (headless) OAuth re-authentication flow using the previously captured refresh token, capturing freshly issued SSO cookies without any victim interaction. This lets the attacker's browser session remain synchronized with a valid Microsoft session indefinitely, and the access effectively survives the victim's password changes, since the underlying OAuth refresh token — not the password — is what is being replayed.
An integrated AI lure-generation feature lets operators generate phishing emails, invoices, business documents, fake voicemail notifications, and password-reset messages directly from the panel, with templates impersonating SharePoint, OneDrive, DocuSign, and Adobe Acrobat Sign, removing the need for external AI tooling or manual lure authoring.
Delivery infrastructure abuses legitimate cloud services to improve deliverability and evade reputation-based blocking: Amazon SES and SendGrid for outbound email/tracking pixels, Cloudflare Pages for phishing landing pages, and a Gophish-based backend for campaign orchestration and click tracking. An AntiBot/evasion layer — described as using AES-encrypted redirectors, bot detection, debugger traps, sandbox checks, and polymorphic code — is designed to block security researchers and automated scanners from reaching the live phishing content; traffic identified as originating from VPN exit nodes is redirected to a benign decoy page instead of the phishing kit.
Observed operator/back-end infrastructure includes the panel domain logfriend[.]com (hosted with an operations presence reported in Kyiv, Ukraine) and at least one instance of device-code phishing activity originating from a Comcast/Xfinity residential IP address in the United States, suggesting either a residential-proxy relay or a US-based operator/reseller. Researchers found feature and workflow overlap with existing PhaaS families Kali365 and Sneaky2
Weaknesses (CWE)
CWE-294, CWE-287, CWE-346
Target sectors: technology, finance, professional-services, government administration, health, education, manufacturing
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1528, T1539, T1557, T1111, T1556, T1550, T1497, T1027