Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Theft
Forg365 Phishing-as-a-Service Targets Microsoft 365 via (TL-2026-1280), also tracked as Forg365 PhaaS, is a high-severity tracked intrusion set, first published 2026-07-13. It is attributed to Forg365 operators with low confidence, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 device authorization, maps to 26 MITRE ATT&CK techniques (T1027, T1071, T1078), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-1280
- Threat ID
- TL-2026-1280
- Also known as
- Forg365 PhaaS
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- Forg365 operators
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, professional-services, government administration, technology, health, manufacturing, retail, education
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Forg365 Phishing-as-a-Service Targets Microsoft 365 via
Malware and tooling: EvilTokens, GPPStorm, Kali365, Sneaky2FA, The Quarry, Forg365, ForgCookie, Gophish, Nyasher
Forg365 is a Telegram-distributed, subscription-based phishing-as-a-service (PhaaS) platform that combines Microsoft OAuth device-code flow abuse, adversary-in-the-middle (AitM) session/cookie theft, a persistent Manifest V3 browser extension (ForgCookie), antibot/VPN-aware traffic filtering, and AI-assisted lure generation to compromise Microsoft 365 accounts and sustain post-compromise mailbox monitoring.
How Forg365 Phishing-as-a-Service Targets Microsoft 365 via works
Forg365 is a commercially operated Phishing-as-a-Service (PhaaS) platform first documented by security researchers at ZeroBEC in July 2026 and sold via Telegram for $400/month or $3,800/year with a 5-day free trial. The operator panel, hosted at logfriend[.]com/login with backend infrastructure traced to Kyiv, Ukraine, provides a full campaign-management workflow: account and link management, invitation handling, OAuth application configuration, redirect-link generation, SVG-based lure assets, campaign send scheduling, SMTP profile configuration and rotation, AI-assisted email generation, a token vault, account intelligence dashboards, keyword-based mailbox alerting, viewer links, and browser-extension support.
Forg365 supports two primary attack branches against Microsoft 365 identities. The first abuses Microsoft's legitimate OAuth 2.0 device-code authentication flow: victims are shown a Microsoft-styled verification-code page and pushed into the genuine Microsoft Authentication Broker sign-in flow, where entering the presented code authorizes an attacker-controlled session without the victim directly disclosing credentials. Sign-in telemetry for this branch shows originalTransferMethod=deviceCodeFlow, and Entra device-registration events tied to campaign activity have used device names prefixed "Forg365-", providing a high-confidence hunting marker. The second branch is a classic adversary-in-the-middle (AitM) reverse-proxy flow using route tokens and session cookies, proxying live authentication traffic and data exchange between the victim and Microsoft identity infrastructure to capture session cookies and tokens in transit, functionally equivalent to prior Sneaky2FA/Kali365-class kits.
Initial access is delivered through phishing emails using legitimate bulk-mail infrastructure — Amazon SES for sending and Twilio SendGrid for hosted tracking images/content — with business-document and remittance-approval lure themes, chained through multiple infrastructure hops (including Cloudflare Pages for landing-page hosting and a Gophish-based delivery component) before reaching Forg365-controlled redirect branches. The kit incorporates AES-encrypted redirectors, automated bot detection, debugger traps, sandbox/anti-analysis checks, polymorphic code, and VPN-aware traffic classification that redirects suspected VPN or security-tooling traffic to benign decoy content instead of the phishing page. Human-verification friction pages reportedly reuse press-and-hold challenge components consistent with the Nyasher antibot framework used across multiple PhaaS families.
Persistence is maintained via ForgCookie, a Manifest V3 browser extension (observed version 1.0.21, compatible with Chrome, Edge, and Brave) whose runtime configuration points to logfriend[.]com as its API base. ForgCookie requests account data from the operator backend, calls a cookie-generation endpoint, clears existing Microsoft session cookies, injects refresh-token-derived credentials, and triggers a silent OAuth re-authentication flow to capture fresh Microsoft SSO cookies across domains — allowing attacker access to survive password resets via refresh-token replay without further victim interaction.
Post-compromise, Forg365 provides operators an account-intelligence dashboard with keyword-based monitoring of compromised mailboxes, AI-drafted reply generation for flagged threads (mirroring the AI-assisted business email compromise workflow documented in the related Kali365 platform, which used Anthropic's Claude to triage and reply to high-value email threads with fraudulent banking details), and direct access to victim mailboxes and cloud data via OWA, OneDrive, and SharePoint using the stolen tokens/cookies.
Forg365 is explicitly positioned by researchers as part of a broader Microsoft 365-focused PhaaS ecosystem that includes Kali365 (also marketed as Octopi365/Freedom365, subject of an FBI/IC3 public service announcement on 2026-05-21 before its operators announced closure), Sneaky2FA, The Quarry, EvilTokens, Nyasher, and GPPStorm — all sharing device-code abuse, AitM cookie theft, and AI-assisted operator tooling as common design patterns. No CVE applies; this is a commercial criminal service abusing legitimate Microsoft authentication flows and legitimate cloud email infrastructure (SES/SendGrid/Cloudflare) rather than exploiting a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1280
Defense Evasion
T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Initial Access
T1078 Valid Accounts; T1566 Phishing
Discovery
T1087 Account Discovery; T1538 Cloud Service Dashboard
Persistence
T1098 Account Manipulation; T1176 Software Extensions
Credential Access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle
Collection
T1114 Email Collection; T1119 Automated Collection; T1213 Data from Information Repositories
Execution
defense-impairment
T1556 Modify Authentication Process; T1685 Disable or Modify Tools
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
Impact
Affected products and versions in Forg365 Phishing-as-a-Service Targets Microsoft 365 via
- Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 device authorization grant)
Vulnerable versions: all tenants with device-code authentication enabled - Google — Chrome (browser extension platform, Manifest V3)
Vulnerable versions: ForgCookie extension installable on any current Chrome release - Microsoft — Edge (browser extension platform, Manifest V3)
Vulnerable versions: ForgCookie extension installable on any current Edge release - Brave Software — Brave (browser extension platform, Manifest V3)
Vulnerable versions: ForgCookie extension installable on any current Brave release
Remediation for Forg365 Phishing-as-a-Service Targets Microsoft 365 via
Immediate actions
- Block or restrict Microsoft Entra ID device-code authentication flow via Conditional Access policies unless explicitly required for kiosk/limited-input scenarios
- Hunt Entra sign-in logs for originalTransferMethod=deviceCodeFlow events from unexpected locations or devices
- Hunt Entra device-registration logs for device names prefixed "Forg365-"
- Revoke and refresh all OAuth refresh tokens and session cookies for any suspected compromised mailbox
- Block/quarantine the logfriend[.]com domain and associated redirect infrastructure at web proxy/DNS/email gateway
- Remove and block the ForgCookie browser extension (Manifest V3, observed version 1.0.21) via browser extension allowlisting/enterprise policy across Chrome, Edge, and Brave
Workarounds
- Disable the device authorization grant flow tenant-wide in Microsoft Entra ID where business need does not require it
Longer-term hardening
- Deploy Conditional Access policies requiring phishing-resistant authentication (FIDO2/passkeys, certificate-based auth) for high-value accounts
- Enforce enterprise browser extension allowlists to prevent unsanctioned OAuth-cookie-manipulating extensions
- Deploy AitM-aware conditional access (token binding / Continuous Access Evaluation) to reduce the value of stolen session cookies
- Monitor for anomalous mailbox rule creation, OWA/OneDrive/SharePoint access patterns, and new OAuth app grants following suspected compromise
- Implement DMARC/DKIM/SPF enforcement and sender reputation monitoring to reduce effectiveness of SES/SendGrid-relayed phishing
- User awareness training specifically covering device-code phishing pretexts, since this technique does not present a traditional fake-login page
Timeline of Forg365 Phishing-as-a-Service Targets Microsoft 365 via
- Huntress publishes research on Kali365, a related Microsoft 365 device-code/AitM PhaaS ecosystem also marketed as Octopi365 and Freedom365; TechRadar covers the kit as the 'Amazon of cybercrime' for its AI-driven MFA-circumvention marketing.
- Paubox reports that Kali365 operators use Anthropic's Claude to triage and reply to high-value compromised-mailbox threads with fraudulent banking details, establishing the AI-assisted BEC pattern later mirrored in Forg365's own AI-drafted-reply feature.
- FBI issues IC3 Public Service Announcement (PSA260521) naming Kali365 as a PhaaS kit hijacking Microsoft 365 access tokens; Kali365 operators announce closure of the platform shortly after the advisory is reposted in their own Telegram channel.
- SpyCloud publishes a post-mortem analysis of Kali365 ('From Telegram Hype to FBI Takedown Theater'), documenting the device-code/AitM kit's architecture shortly after its shutdown announcement.
- BleepingComputer, CyberPress, GBHackers, Cybersecurity News, Windows Report, and Windows Forum publish independent coverage summarizing Forg365's device-code abuse, AitM routing, ForgCookie extension, and AI lure generation.
- SoCRadar publishes an IOC Radar report cataloguing Forg365 device-code-flow abuse indicators alongside the initial ZeroBEC disclosure.
- ZeroBEC researchers publish 'Inside Forg365', documenting the Telegram-distributed, Sneaky2FA-style PhaaS platform after tracing a business-document-themed phishing email to the Forg365 operator panel.
- CyberReplay publishes an incident-response and mitigation playbook specific to Forg365 AitM and device-code phishing against Microsoft 365 tenants.
- The Hacker News publishes aggregated coverage of the Forg365 campaign, consolidating device-code and AitM session-theft findings for broader distribution.
Sources cited for Forg365 Phishing-as-a-Service Targets Microsoft 365 via
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
- Inside Forg365: A Telegram-Distributed Sneaky2FA-Style PhaaS Targeting Microsoft 365
- New Forg365 phishing platform uses AI to target Microsoft 365 accounts
- Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions
- Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts
- Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts
- Forg365 Phishing Platform Targets Microsoft 365 Accounts With AI and Device-Code Abuse
- Forg365 Hijacks Microsoft 365 Sessions via Device-Code Phishing
- Mitigating Forg365 AiTM & Device-Code Phishing Against Microsoft 365: Detection, Controls, and Incident Playbook
- Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions (IOC Radar)
- Inside Kali365, a Device Code Phishing Ecosystem
- Internet Crime Complaint Center (IC3) | Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
- Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit - From Telegram Hype to FBI Takedown Theater
- Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication
- Kali365 uses Claude AI to launch fraud from victims' own inboxes
Threats related to Forg365 Phishing-as-a-Service Targets Microsoft 365 via
- Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent Offenders
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
Detection coverage for TL-2026-1280
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1280 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.