Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise …
Intelligence analysis by Llama

Forg365 is a PhaaS kit that uses legitimate email delivery infrastructure, such as Amazon Simple Email Service (Amazon SES) and Twilio SendGrid, to imitate a redirection chain that blends into regular email traffic before it ends in Forg365-controlled domains. The kit is designed for continued access to compromised accounts and offers an extension named ForgCookie for Chromium-based b…
Forg365 is a phishing kit that tricks people into giving away their Microsoft 365 account information. It uses fake emails that look like they're from Microsoft, but are actually controlled by the attackers. The attackers then use this information to access the victim's account and do bad things.
Analysis
A Mature Operator Workflow
The Forg365 PhaaS kit is a mature operator workflow that exposes a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations. This kit is designed to lower the skill threshold while increasing operational consistency, making it accessible to even threat actors with little-to-no technical expertise.
Device Code Phishing
The Forg365 platform employs device-auth phishing, which presents a Microsoft-styled verification code page and pushes the victim into a legitimate Microsoft Authentication Broker sign-in flow. The victim sees real Microsoft authentication surfaces, but the code authorizes an attacker-controlled session.
AitM Phishing
The platform employs route tokens, session cookies, and traffic classification to determine whether to serve phishing content or a benign decoy. If a VPN connection is detected, the kit redirects to innocuous decoy content instead of exposing the phishing pages.
Post-Compromise Actions
Forg365 extends beyond simple credential and token harvesting to facilitate a wide array of post-compromise actions, including monitoring for specific keywords in compromised email accounts and drafting a message response to a particular email thread using assistance from AI. The result is a platform that lowers the skill threshold while increasing operational consistency.
Key points
- Forg365 is a PhaaS kit that targets Microsoft 365 accounts
- The kit uses device code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations
- The kit is designed to lower the skill threshold while increasing operational consistency
- The kit offers an extension named ForgCookie for Chromium-based browsers
- The kit facilitates post-compromise actions, including monitoring for specific keywords and drafting message responses using AI
If the Forg365 PhaaS kit is shut down, it could reduce the number of phishing attacks targeting Microsoft 365 accounts. This could lead to a decrease in the number of compromised accounts and a reduction in the financial losses associated with these attacks.
If the Forg365 PhaaS kit is not shut down, it could continue to evolve and become even more sophisticated, making it harder to detect and prevent phishing attacks. This could lead to a significant increase in the number of compromised accounts and financial losses.



