Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Theft

Forg365 Phishing-as-a-Service Targets Microsoft 365 via (TL-2026-1280), also tracked as Forg365 PhaaS, is a high-severity tracked intrusion set, first published 2026-07-13. It is attributed to Forg365 operators with low confidence, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 device authorization, maps to 26 MITRE ATT&CK techniques (T1027, T1071, T1078), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1280

Threat ID
TL-2026-1280
Also known as
Forg365 PhaaS
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
Forg365 operators
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, professional-services, government administration, technology, health, manufacturing, retail, education
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in Forg365 Phishing-as-a-Service Targets Microsoft 365 via

Malware and tooling: EvilTokens, GPPStorm, Kali365, Sneaky2FA, The Quarry, Forg365, ForgCookie, Gophish, Nyasher

Forg365 is a Telegram-distributed, subscription-based phishing-as-a-service (PhaaS) platform that combines Microsoft OAuth device-code flow abuse, adversary-in-the-middle (AitM) session/cookie theft, a persistent Manifest V3 browser extension (ForgCookie), antibot/VPN-aware traffic filtering, and AI-assisted lure generation to compromise Microsoft 365 accounts and sustain post-compromise mailbox monitoring.

How Forg365 Phishing-as-a-Service Targets Microsoft 365 via works

Forg365 is a commercially operated Phishing-as-a-Service (PhaaS) platform first documented by security researchers at ZeroBEC in July 2026 and sold via Telegram for $400/month or $3,800/year with a 5-day free trial. The operator panel, hosted at logfriend[.]com/login with backend infrastructure traced to Kyiv, Ukraine, provides a full campaign-management workflow: account and link management, invitation handling, OAuth application configuration, redirect-link generation, SVG-based lure assets, campaign send scheduling, SMTP profile configuration and rotation, AI-assisted email generation, a token vault, account intelligence dashboards, keyword-based mailbox alerting, viewer links, and browser-extension support.

Forg365 supports two primary attack branches against Microsoft 365 identities. The first abuses Microsoft's legitimate OAuth 2.0 device-code authentication flow: victims are shown a Microsoft-styled verification-code page and pushed into the genuine Microsoft Authentication Broker sign-in flow, where entering the presented code authorizes an attacker-controlled session without the victim directly disclosing credentials. Sign-in telemetry for this branch shows originalTransferMethod=deviceCodeFlow, and Entra device-registration events tied to campaign activity have used device names prefixed "Forg365-", providing a high-confidence hunting marker. The second branch is a classic adversary-in-the-middle (AitM) reverse-proxy flow using route tokens and session cookies, proxying live authentication traffic and data exchange between the victim and Microsoft identity infrastructure to capture session cookies and tokens in transit, functionally equivalent to prior Sneaky2FA/Kali365-class kits.

Initial access is delivered through phishing emails using legitimate bulk-mail infrastructure — Amazon SES for sending and Twilio SendGrid for hosted tracking images/content — with business-document and remittance-approval lure themes, chained through multiple infrastructure hops (including Cloudflare Pages for landing-page hosting and a Gophish-based delivery component) before reaching Forg365-controlled redirect branches. The kit incorporates AES-encrypted redirectors, automated bot detection, debugger traps, sandbox/anti-analysis checks, polymorphic code, and VPN-aware traffic classification that redirects suspected VPN or security-tooling traffic to benign decoy content instead of the phishing page. Human-verification friction pages reportedly reuse press-and-hold challenge components consistent with the Nyasher antibot framework used across multiple PhaaS families.

Persistence is maintained via ForgCookie, a Manifest V3 browser extension (observed version 1.0.21, compatible with Chrome, Edge, and Brave) whose runtime configuration points to logfriend[.]com as its API base. ForgCookie requests account data from the operator backend, calls a cookie-generation endpoint, clears existing Microsoft session cookies, injects refresh-token-derived credentials, and triggers a silent OAuth re-authentication flow to capture fresh Microsoft SSO cookies across domains — allowing attacker access to survive password resets via refresh-token replay without further victim interaction.

Post-compromise, Forg365 provides operators an account-intelligence dashboard with keyword-based monitoring of compromised mailboxes, AI-drafted reply generation for flagged threads (mirroring the AI-assisted business email compromise workflow documented in the related Kali365 platform, which used Anthropic's Claude to triage and reply to high-value email threads with fraudulent banking details), and direct access to victim mailboxes and cloud data via OWA, OneDrive, and SharePoint using the stolen tokens/cookies.

Forg365 is explicitly positioned by researchers as part of a broader Microsoft 365-focused PhaaS ecosystem that includes Kali365 (also marketed as Octopi365/Freedom365, subject of an FBI/IC3 public service announcement on 2026-05-21 before its operators announced closure), Sneaky2FA, The Quarry, EvilTokens, Nyasher, and GPPStorm — all sharing device-code abuse, AitM cookie theft, and AI-assisted operator tooling as common design patterns. No CVE applies; this is a commercial criminal service abusing legitimate Microsoft authentication flows and legitimate cloud email infrastructure (SES/SendGrid/Cloudflare) rather than exploiting a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1280

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1078 Valid Accounts; T1566 Phishing

Discovery

T1087 Account Discovery; T1538 Cloud Service Dashboard

Persistence

T1098 Account Manipulation; T1176 Software Extensions

Credential Access

T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle

Collection

T1114 Email Collection; T1119 Automated Collection; T1213 Data from Information Repositories

Execution

T1204 User Execution

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

Affected products and versions in Forg365 Phishing-as-a-Service Targets Microsoft 365 via

  • Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 device authorization grant)
    Vulnerable versions: all tenants with device-code authentication enabled
  • Google — Chrome (browser extension platform, Manifest V3)
    Vulnerable versions: ForgCookie extension installable on any current Chrome release
  • Microsoft — Edge (browser extension platform, Manifest V3)
    Vulnerable versions: ForgCookie extension installable on any current Edge release
  • Brave Software — Brave (browser extension platform, Manifest V3)
    Vulnerable versions: ForgCookie extension installable on any current Brave release

Remediation for Forg365 Phishing-as-a-Service Targets Microsoft 365 via

Immediate actions

  • Block or restrict Microsoft Entra ID device-code authentication flow via Conditional Access policies unless explicitly required for kiosk/limited-input scenarios
  • Hunt Entra sign-in logs for originalTransferMethod=deviceCodeFlow events from unexpected locations or devices
  • Hunt Entra device-registration logs for device names prefixed "Forg365-"
  • Revoke and refresh all OAuth refresh tokens and session cookies for any suspected compromised mailbox
  • Block/quarantine the logfriend[.]com domain and associated redirect infrastructure at web proxy/DNS/email gateway
  • Remove and block the ForgCookie browser extension (Manifest V3, observed version 1.0.21) via browser extension allowlisting/enterprise policy across Chrome, Edge, and Brave

Workarounds

  • Disable the device authorization grant flow tenant-wide in Microsoft Entra ID where business need does not require it

Longer-term hardening

  • Deploy Conditional Access policies requiring phishing-resistant authentication (FIDO2/passkeys, certificate-based auth) for high-value accounts
  • Enforce enterprise browser extension allowlists to prevent unsanctioned OAuth-cookie-manipulating extensions
  • Deploy AitM-aware conditional access (token binding / Continuous Access Evaluation) to reduce the value of stolen session cookies
  • Monitor for anomalous mailbox rule creation, OWA/OneDrive/SharePoint access patterns, and new OAuth app grants following suspected compromise
  • Implement DMARC/DKIM/SPF enforcement and sender reputation monitoring to reduce effectiveness of SES/SendGrid-relayed phishing
  • User awareness training specifically covering device-code phishing pretexts, since this technique does not present a traditional fake-login page

Timeline of Forg365 Phishing-as-a-Service Targets Microsoft 365 via

  • Huntress publishes research on Kali365, a related Microsoft 365 device-code/AitM PhaaS ecosystem also marketed as Octopi365 and Freedom365; TechRadar covers the kit as the 'Amazon of cybercrime' for its AI-driven MFA-circumvention marketing.
  • Paubox reports that Kali365 operators use Anthropic's Claude to triage and reply to high-value compromised-mailbox threads with fraudulent banking details, establishing the AI-assisted BEC pattern later mirrored in Forg365's own AI-drafted-reply feature.
  • FBI issues IC3 Public Service Announcement (PSA260521) naming Kali365 as a PhaaS kit hijacking Microsoft 365 access tokens; Kali365 operators announce closure of the platform shortly after the advisory is reposted in their own Telegram channel.
  • SpyCloud publishes a post-mortem analysis of Kali365 ('From Telegram Hype to FBI Takedown Theater'), documenting the device-code/AitM kit's architecture shortly after its shutdown announcement.
  • BleepingComputer, CyberPress, GBHackers, Cybersecurity News, Windows Report, and Windows Forum publish independent coverage summarizing Forg365's device-code abuse, AitM routing, ForgCookie extension, and AI lure generation.
  • SoCRadar publishes an IOC Radar report cataloguing Forg365 device-code-flow abuse indicators alongside the initial ZeroBEC disclosure.
  • ZeroBEC researchers publish 'Inside Forg365', documenting the Telegram-distributed, Sneaky2FA-style PhaaS platform after tracing a business-document-themed phishing email to the Forg365 operator panel.
  • CyberReplay publishes an incident-response and mitigation playbook specific to Forg365 AitM and device-code phishing against Microsoft 365 tenants.
  • The Hacker News publishes aggregated coverage of the Forg365 campaign, consolidating device-code and AitM session-theft findings for broader distribution.

Sources cited for Forg365 Phishing-as-a-Service Targets Microsoft 365 via

Threats related to Forg365 Phishing-as-a-Service Targets Microsoft 365 via

Detection coverage for TL-2026-1280

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1280 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats