A Sophisticated Phishing Platform Emerges with AI-Powered Lure Generation
Cybersecurity researchers have uncovered a new phishing-as-a-service (PhaaS) operation called Forg365 that’s specifically designed to target Microsoft 365 accounts. What sets this platform apart is its use of artificial intelligence (AI) to craft custom phishing lures, making it more convincing and harder to detect.
Forg365 combines two types of phishing methods: adversary-in-the-middle (AiTM) and device code phishing. The AI-powered lure generation feature allows the attackers to create tailored emails that mimic legitimate business communications. These emails often use Amazon SES for delivery and SendGrid-hosted images or tracking resources, making them blend in seamlessly with regular email traffic.
The platform’s dashboard provides a range of features, including the ability to manage tokens, configure OAuth apps, and generate phishing emails with AI assistance. This integration is strategic, as it reduces the cost of developing custom phishing content and building PhaaS platforms. Forg365 also includes an account intelligence dashboard that scans compromised mailboxes for predefined terms, alerting operators whenever a match is detected.
One of the most concerning aspects of Forg365 is its use of a browser extension called ForgCookie. This extension automatically refreshes Microsoft SSO cookies, providing persistent access to the victim’s Microsoft services without requiring re-authentication. The extension works by requesting account data from the Forg365 backend, clearing session cookies, and triggering a silent OAuth flow to capture fresh cookies.
Forg365 supports two primary attack paths: device-code phishing and AiTM phishing. In device-code phishing, victims are tricked into authorizing an attacker-controlled gadget through Microsoft’s legitimate OAuth 2.0 device code flow authentication method. For AiTM phishing, the platform uses a proxy for authentication requests and data exchanged between Microsoft infrastructure and the target account, capturing session cookies in the process.
To prevent researchers from accessing its administration panel, Forg365 employs various anti-bot features, including AES-encrypted redirectors, bot detection, debugger traps, sandbox checks, and polymorphic code. The platform also leverages Amazon SES for phishing email delivery, Cloudflare Pages for landing pages, and Gophish infrastructure for campaign delivery.
To protect yourself from this type of attack, it’s essential to be aware of the risks associated with Microsoft device-code authentication. Users are recommended to restrict or disable this feature unless required. Regularly monitoring Microsoft Entra logs for device-code authentication events is also crucial. Additionally, mailbox rules, new device sign-ins, and OAuth grants should be investigated for unexpected entries.
If you suspect your account has been compromised, all tokens and sessions must be revoked and re-authenticated as soon as possible. Staying vigilant and taking proactive measures to secure your Microsoft 365 accounts can help mitigate the risks associated with this sophisticated phishing platform.
Source: Bleeping Computer — 2026-07-09