What is Forg365 and why does it matter?
Forg365 is a recently reported Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 users through Device Code Authentication abuse, Adversary-in-the-Middle (AitM) phishing, session cookie theft, and token hijacking.
Forg365 is distributed through Telegram and gives attackers a ready-made phishing toolkit.
It can create AI-written phishing messages, manage campaigns, steal tokens, and monitor compromised mailboxes.
This shows how phishing is shifting toward identity-based attacks on cloud and Microsoft 365 environments.
Who is most at risk from Forg365 phishing attacks?
This threat is particularly relevant to:
- Microsoft 365 Administrators
- Security Operations Center (SOC) Teams
- Incident Response Teams
- CISOs and Security Leadership
- Identity and Access Management (IAM) Teams
- Exchange Online Administrators
- Organizations using Microsoft Entra ID (Azure AD)
- Financial Services, Healthcare, Manufacturing, Education, and Government sectors
- Organizations with remote or hybrid workforces
How does the Forg365 phishing campaign work?
Attackers leverage Forg365 to deliver phishing emails using regular email delivery services such as Amazon SES and Twilio SendGrid.
Phishing emails commonly impersonate business documents, payment approvals, and collaboration requests to make users click malicious links.
What attack techniques does Forg365 use?
- Phishing emails delivered through trusted services such as Amazon SES and SendGrid.
- Device Code Authentication phishing that tricks users into authorizing attacker-controlled sessions.
- Adversary-in-the-Middle (AitM) phishing designed to intercept authenticated Microsoft 365 sessions.
- Session cookies and OAuth token theft for persistent access.
- Anti-bot and VPN-detection mechanisms are used to evade automated analysis.
- Decoy pages are displayed when security researchers or sandbox environments are detected.
Why is Forg365 different from traditional phishing?
- Utilizes legitimate Microsoft authentication pages, increasing user trust.
- Does not rely solely on password theft.
- Captures valid authentication tokens and session cookies after successful MFA completion.
- Includes a browser extension called ForgCookie that automates cookie injection and session persistence.
- Supports mailbox monitoring, account intelligence gathering, and AI-assisted email responses from compromised accounts.
What should security teams know about Forg365?
- The platform is offered commercially as a subscription-based service.
- Operator panels allow threat actors to manage phishing campaigns with minimal technical knowledge.
- The campaign demonstrates increasing abuse of Device Code Authentication workflows.
- Traditional password protection and MFA alone may not prevent compromise when session tokens are stolen.
Known indicators of compromise for Forg365
Domain:
Behavioral Indicators:
- Unexpected Device Code Authentication activity.
- Unusual Microsoft Authentication Broker sign-ins.
- New or unexpected OAuth consent grants.
- Suspicious mailbox forwarding or inbox rules.
- Abnormal access to Exchange Online, OneDrive, or SharePoint.
- Unauthorized browser extension installations.
- Internal phishing or unusual outbound email from a trusted account.
Why is Forg365 a risk to Microsoft 365 environments?
Account Takeover – Attackers can gain full access to Microsoft 365 accounts without needing the victim’s password after getting valid session tokens and authentication cookies.
Business Email Compromise (BEC): Compromised mailboxes may be used to conduct internal phishing campaigns, invoice fraud, executive impersonation, and vendor payment scams.
Data Exposure: Threat actors may access sensitive emails, intellectual property, financial information, customer data, and confidential communications stored within Microsoft 365 services.
Operational Impact: Unauthorized access to mailboxes can disrupt business operations, slow down incident response, and help attackers stay hidden in cloud environments for longer.
Reputational and Financial Risk: A compromised account can lead to compliance issues, damage the organization’s reputation, reduce customer trust, create legal risks, and cause financial loss.
Are your Microsoft 365 risks hiding in plain sight?
ProArch can assess your environment, uncover identity and access gaps, and prioritize the fixes that matter most.
Assess your Microsoft 365 Security
How can organizations protect against Forg365 phishing attacks?
Immediate Recommendations (0–30 Days)
- Monitor Device Code Authentication events.
- Investigate suspicious Microsoft Authentication Broker sign-ins.
- Audit recent OAuth permissions and consent grants.
- Review mailbox forwarding, inbox rules, and delegation.
- Restrict Device Code Authentication where not required.
- Revoke active sessions and refresh tokens.
- Alert on mailbox-rule creation and OAuth consent.
- Hunt for activity involving logfriend[.]com.
Short-Term Recommendations (1–3 Months)
- Restrict access from unmanaged devices with Conditional Access.
- Require compliant devices for Microsoft 365 access.
- Review enterprise app permissions and consent grants.
- Improve monitoring for token theft and session abuse.
- Train users to spot Device Code Authentication phishing.
Mid / Long-Term Recommendations (3–12 Months)
- Automate detection for Device Code Authentication abuse.
- Apply Zero Trust controls across cloud services.
- Use advanced identity threat detection and risk monitoring.
- Schedule regular audits of OAuth apps and third-party integrations.
- Expand training to cover MFA bypass and session hijacking.
What Forg365 phishing trends should teams monitor next?
- Growth of Device Code Phishing campaigns targeting Microsoft 365.
- Emergence of new phishing kits that steal OAuth tokens.
- Misuse of Microsoft Authentication Broker and OAuth authorization flows.
- Expansion of phishing-as-a-service ecosystems such as Forg365, Kali365, Sneaky2FA, and EvilTokens.
- Increased use of AI-generated phishing content and automated post-compromise operations.
Strengthen your Microsoft 365 security posture with ProArch
Forg365 shows why Microsoft 365 security must go beyond passwords and MFA. ProArch helps organizations assess identity risks, harden cloud access, and strengthen defenses across Microsoft 365.
From Microsoft Entra ID and Conditional Access to Defender, Sentinel, Purview, Zero Trust, and managed security operations, ProArch can help you identify gaps and prioritize remediation.
Talk to ProArch to strengthen your Microsoft 365 defenses