Phishing Platform Forg365 Uses AI to Target Microsoft 365 Accounts with Sophisticated Tactics
A new phishing-as-a-service operation has emerged, targeting unsuspecting users of Microsoft 365 accounts with an arsenal of sophisticated tactics. The platform, called Forg365, combines artificial intelligence (AI) with traditional phishing methods to trick victims into handing over their login credentials.
Forg365’s AI-powered phishing lures are designed to mimic legitimate emails from trusted services, making them nearly indistinguishable from the real thing. Researchers at ZeroBEC email security company discovered that the platform uses a combination of Amazon SES delivery and SendGrid-hosted images or tracking resources to make its messages appear authentic. This blending of legitimate services with phishing infrastructure indicates a mature operation capable of evading detection.
The platform’s capabilities are extensive, featuring device-code phishing, adversary-in-the-middle (AiTM) phishing, AI-assisted email content generation, token and cookie management, and post-compromise operations. Forg365 also includes an account intelligence dashboard and keyword monitoring feature that alerts operators when specific terms are detected in compromised mailboxes.
One of the most concerning features of Forg365 is its use of a browser extension called ForgCookie, which provides attackers with persistent access to Microsoft services associated with the victim’s account. The extension works by requesting account data from the Forg365 backend, clearing session cookies, and triggering a silent OAuth flow to capture fresh cookies. This allows the attacker to maintain unauthorized access to the compromised account without needing to re-authenticate.
Researchers also found that Forg365 supports two primary attack paths: device-code phishing and AiTM phishing. In device-code phishing, victims are tricked into authorizing an attacker-controlled gadget through Microsoft’s legitimate OAuth 2.0 device code flow authentication method. In AiTM phishing, the platform uses a proxy for authentication requests and data exchanged between the Microsoft infrastructure and the target account, capturing session cookies in the process.
To prevent detection, Forg365 has implemented various countermeasures, including an AntiBot feature that boasts AES-encrypted redirectors, bot detection, debugger traps, sandbox checks, and polymorphic code. The platform also leverages Amazon SES for phishing email delivery, Cloudflare Pages for landing pages, and Gophish infrastructure for campaign delivery.
To protect against Forg365’s tactics, Microsoft 365 users are advised to restrict or disable device-code authentication unless absolutely necessary. Monitoring Microsoft Entra logs for device-code authentication events is also crucial, as well as investigating mailbox rules, new device sign-ins, Microsoft Authentication Broker activity, and OAuth grants for unexpected entries. If a compromise is suspected, all tokens and sessions must be revoked and re-authenticated to prevent further unauthorized access.
Source: Bleeping Computer — 2026-07-09