New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
Intelligence analysis by Llama

Forg365 is a mature PhaaS operation that uses AI to craft custom phishing lures and provides a browser extension for continued access to Microsoft services linked to compromised accounts.
Imagine you receive an email that looks like it's from a trusted service, but it's actually a trick to get you to give away your Microsoft 365 account information. This is called phishing, and it's a way for bad people to get access to your account. Forg365 is a new tool that helps these bad people make these fake emails look more real, making it harder for you to tell the difference.
Analysis
A New Phishing Threat Emerges
Forg365 is a new phishing-as-a-service (PhaaS) operation that has been discovered by researchers at ZeroBEC. This platform focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. The platform's use of AI to craft custom phishing lures makes it a sophisticated threat that can blend in with regular email traffic.
How Forg365 Works
The Forg365 platform features device-code phishing, adversary-in-the-Middle (AiTM) phishing, AI-assisted email content generation, token and cookie management, and post-compromise operations. The platform's dashboard allows operators to create new phishing campaigns, manage phishing links, configure OAuth apps and SMTP profiles, manage tokens, and generate phishing emails with the help of AI. The integration of AI in Forg365's panel is strategic, as it reduces the cost of developing custom phishing content and building custom PhaaS platforms.
The ForgCookie Extension
The Forg365 platform also includes a browser extension called ForgCookie that is compatible with Google Chrome, Microsoft Edge, and Brave. This extension is specifically designed for automatically refreshing Microsoft SSO cookies and provides the attacker with persistent access to the Microsoft services associated with the victim's account. The extension works by requesting account data from the Forg365 backend, clearing session cookies, and triggering a silent OAuth flow to capture the fresh cookies.
The Threat of Forg365
The Forg365 platform is a significant threat to Microsoft 365 users, as it uses AI to craft custom phishing lures and provides a browser extension for continued access to Microsoft services linked to compromised accounts. The platform's use of device-code phishing and AiTM phishing makes it a sophisticated threat that can evade detection. Therefore, it is essential to stay vigilant against this threat and take necessary precautions to protect against phishing attacks.
Key points
- Forg365 is a new phishing-as-a-service (PhaaS) operation that uses AI to craft custom phishing lures.
- The platform provides a browser extension for continued access to Microsoft services linked to compromised accounts.
- Forg365 uses device-code phishing and AiTM phishing to evade detection.
- The platform's use of AI makes it a sophisticated threat that can blend in with regular email traffic.
- Users are recommended to restrict or disable Microsoft device-code authentication unless required and to monitor Microsoft Entra logs for device-code authentication events.
If this development plays out positively, Microsoft may be able to improve its security measures to prevent such phishing attacks. Additionally, the discovery of Forg365 may lead to a greater awareness of the threat of AI-assisted phishing attacks, prompting users to be more vigilant and take necessary precautions to protect themselves.
The use of AI in phishing attacks like Forg365 makes it a sophisticated threat that can evade detection. If this development plays out negatively, it may lead to a significant increase in phishing attacks, causing users to lose their Microsoft 365 account information and compromising their security.



