Executive Summary
Forg365 is a sophisticated Microsoft 365-focused Phishing-as-a-Service (PhaaS) platform distributed via Telegram. It represents a significant evolution in phishing tradecraft by integrating AI-assisted lure generation directly into its operator panel and supporting both Adversary-in-the-Middle (AiTM) and device-code phishing branches. The platform is commercially packaged with subscription tiers, mirroring the delivery models of established threats like Kali365 and Sneaky 2FA.
Technically, the platform automates the full attack lifecycle, from initial delivery via Amazon SES and SendGrid to post-compromise mailbox operations. A notable feature is 'ForgCookie,' a Manifest V3 browser extension designed to automate Microsoft SSO cookie refreshing, ensuring persistent access for attackers even after initial session expiry. The platform also employs robust AntiBot measures and traffic classification, redirecting VPN or analyst traffic to benign decoys such as SpaceX-themed pages.
This threat is high-priority for organizations relying on Microsoft 365. Forg365 specifically abuses the high-risk device-code authentication flow to bypass traditional MFA, and its integration of AI-driven automation lowers the barrier for entry for less skilled affiliates. Defenders must shift from treating phishing as a user-awareness issue to an identity-risk control priority, focusing on blocking high-risk authentication methods and monitoring for specific platform artifacts like Forg365-prefixed device registrations.
