Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Theft — Threadlinqs Intelligence
As of 2026-07-13, Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Theft is a high-severity threat intel threat attributed to Forg365 operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1280 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Forg365 operators · FINANCIAL
Forg365 is a Telegram-distributed, subscription-based phishing-as-a-service (PhaaS) platform that combines Microsoft OAuth device-code flow abuse, adversary-in-the-middle (AitM) session/cookie theft,
Forg365 is a commercially operated Phishing-as-a-Service (PhaaS) platform first documented by security researchers at ZeroBEC in July 2026 and sold via Telegram for $400/month or $3,800/year with a 5-day free trial. The operator panel, hosted at logfriend[.]com/login with backend infrastructure traced to Kyiv, Ukraine, provides a full campaign-management workflow: account and link management, invitation handling, OAuth application configuration, redirect-link generation, SVG-based lure assets, campaign send scheduling, SMTP profile configuration and rotation, AI-assisted email generation, a token vault, account intelligence dashboards, keyword-based mailbox alerting, viewer links, and browser-extension support.
Forg365 supports two primary attack branches against Microsoft 365 identities. The first abuses Microsoft's legitimate OAuth 2.0 device-code authentication flow: victims are shown a Microsoft-styled verification-code page and pushed into the genuine Microsoft Authentication Broker sign-in flow, where entering the presented code authorizes an attacker-controlled session without the victim directly disclosing credentials. Sign-in telemetry for this branch shows originalTransferMethod=deviceCodeFlow, and Entra device-registration events tied to campaign activity have used device names prefixed "Forg365-", providing a high-confidence hunting marker. The second branch is a classic adversary-in-the-middle (AitM) reverse-proxy flow using route tokens and session cookies, proxying live authentication traffic and data exchange between the victim and Microsoft identity infrastructure to capture session cookies and tokens in transit, functionally equivalent to prior Sneaky2FA/Kali365-class kits.
Initial access is delivered through phishing emails using legitimate bulk-mail infrastructure — Amazon SES for sending and Twilio SendGrid for hosted tracking images/content — with business-document and remittance-approval lure themes, chained through multiple infrastructure hops (including Cloudflare Pages for landing-page hosting and a Gophish-based delivery component) before reaching Forg365-controlled redirect branches. The kit incorporates AES-encrypted redirectors, automated bot detection, debugger traps, sandbox/anti-analysis checks, polymorphic code, and VPN-aware traffic classification that redirects suspected VPN or security-tooling traffic to benign decoy content instead of the phishing page. Human-verification friction pages reportedly reuse press-and-hold challenge components consistent with the Nyasher antibot framework used across multiple PhaaS families.
Persistence is maintained via ForgCookie, a Manifest V3 browser extension (observed version 1.0.21, compatible with Chrome, Edge, and Brave) whose runtime configuration points to logfriend[.]com as its API base. ForgCookie requests account data from the operator backend, calls a cookie-generation endpoint, clears existing Microsoft session cookies, injects refresh-token-derived credentials, and triggers a silent OAuth re-authentication flow to capture fresh Microsoft SSO cookies across domains — allowing attacker access to survive password resets via refresh-token replay without further victim interaction.
Post-compromise, Forg365 provides operators an account-intelligence dashboard with keyword-based monitoring of compromised mailboxes, AI-drafted reply generation for flagged threads (mirroring the AI-assisted business email compromise workflow documented in the related Kali365 platform, which used Anthropic's Claude to triage and reply to high-value email threads with fraudulent banking details), and direct access to victim mailboxes and cloud data via OWA, OneDrive, and SharePoint using the stolen tokens/cookies.
Forg365 is explicitly positioned by researchers as part of a broader Microsoft 365-focused PhaaS ecosystem that includes Kali365 (also marketed as Octopi365/Freedom365, subject of an FBI/IC3 public service announcement on 2026-05-21 before its operators ann
Target sectors: finance, professional-services, government administration, technology, health, manufacturing, retail, education
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1587, T1585, T1584, T1566, T1078, T1204, T1176, T1098