discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.

By Bill Toulas·Jul 9·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

New Forg365 phishing platform uses AI to target Microsoft 365 accounts
Image: bleepingcomputer.com

Forg365 is a mature PhaaS operation that uses AI to craft custom phishing lures and provides a browser extension for continued access to Microsoft services linked to compromised accounts.

Why it matters

This story matters because it highlights the growing threat of AI-assisted phishing attacks and the importance of staying vigilant against sophisticated cyber threats.

Imagine you receive an email that looks like it's from a trusted service, but it's actually a trick to get you to give away your Microsoft 365 account information. This is called phishing, and it's a way for bad people to get access to your account. Forg365 is a new tool that helps these bad people make these fake emails look more real, making it harder for you to tell the difference.

Analysis

A New Phishing Threat Emerges

Forg365 is a new phishing-as-a-service (PhaaS) operation that has been discovered by researchers at ZeroBEC. This platform focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. The platform's use of AI to craft custom phishing lures makes it a sophisticated threat that can blend in with regular email traffic.

How Forg365 Works

The Forg365 platform features device-code phishing, adversary-in-the-Middle (AiTM) phishing, AI-assisted email content generation, token and cookie management, and post-compromise operations. The platform's dashboard allows operators to create new phishing campaigns, manage phishing links, configure OAuth apps and SMTP profiles, manage tokens, and generate phishing emails with the help of AI. The integration of AI in Forg365's panel is strategic, as it reduces the cost of developing custom phishing content and building custom PhaaS platforms.

The ForgCookie Extension

The Forg365 platform also includes a browser extension called ForgCookie that is compatible with Google Chrome, Microsoft Edge, and Brave. This extension is specifically designed for automatically refreshing Microsoft SSO cookies and provides the attacker with persistent access to the Microsoft services associated with the victim's account. The extension works by requesting account data from the Forg365 backend, clearing session cookies, and triggering a silent OAuth flow to capture the fresh cookies.

The Threat of Forg365

The Forg365 platform is a significant threat to Microsoft 365 users, as it uses AI to craft custom phishing lures and provides a browser extension for continued access to Microsoft services linked to compromised accounts. The platform's use of device-code phishing and AiTM phishing makes it a sophisticated threat that can evade detection. Therefore, it is essential to stay vigilant against this threat and take necessary precautions to protect against phishing attacks.

Key points

  • Forg365 is a new phishing-as-a-service (PhaaS) operation that uses AI to craft custom phishing lures.
  • The platform provides a browser extension for continued access to Microsoft services linked to compromised accounts.
  • Forg365 uses device-code phishing and AiTM phishing to evade detection.
  • The platform's use of AI makes it a sophisticated threat that can blend in with regular email traffic.
  • Users are recommended to restrict or disable Microsoft device-code authentication unless required and to monitor Microsoft Entra logs for device-code authentication events.
The Upside

If this development plays out positively, Microsoft may be able to improve its security measures to prevent such phishing attacks. Additionally, the discovery of Forg365 may lead to a greater awareness of the threat of AI-assisted phishing attacks, prompting users to be more vigilant and take necessary precautions to protect themselves.

The Downside

The use of AI in phishing attacks like Forg365 makes it a sophisticated threat that can evade detection. If this development plays out negatively, it may lead to a significant increase in phishing attacks, causing users to lose their Microsoft 365 account information and compromising their security.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentssecurityphishingmicrosoft-365ai-assisted-phishing

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Jul 9, 2026

Source

bleepingcomputer.com

Share

Topics

ai-agentssecurityphishingmicrosoft-365ai-assisted-phishing

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.