Forg365 PhaaS Targets Microsoft 365 Accounts
Score: 9/10

Forg365 PhaaS Targets Microsoft 365 Accounts

The Forg365 Phishing-as-a-Service platform utilizes AI-assisted lures, device-code flow abuse, and a custom browser extension to compromise and maintain access to Microsoft 365 environments.

Executive Summary

Forg365 is a sophisticated Microsoft 365-focused Phishing-as-a-Service (PhaaS) platform distributed via Telegram. It represents a significant evolution in phishing tradecraft by integrating AI-assisted lure generation directly into its operator panel and supporting both Adversary-in-the-Middle (AiTM) and device-code phishing branches. The platform is commercially packaged with subscription tiers, mirroring the delivery models of established threats like Kali365 and Sneaky 2FA.

Technically, the platform automates the full attack lifecycle, from initial delivery via Amazon SES and SendGrid to post-compromise mailbox operations. A notable feature is 'ForgCookie,' a Manifest V3 browser extension designed to automate Microsoft SSO cookie refreshing, ensuring persistent access for attackers even after initial session expiry. The platform also employs robust AntiBot measures and traffic classification, redirecting VPN or analyst traffic to benign decoys such as SpaceX-themed pages.

This threat is high-priority for organizations relying on Microsoft 365. Forg365 specifically abuses the high-risk device-code authentication flow to bypass traditional MFA, and its integration of AI-driven automation lowers the barrier for entry for less skilled affiliates. Defenders must shift from treating phishing as a user-awareness issue to an identity-risk control priority, focusing on blocking high-risk authentication methods and monitoring for specific platform artifacts like Forg365-prefixed device registrations.

Key Details

Threat Name

Forg365 PhaaS

Affects

—

Adversary

Forg365 Other Adversaries and Aliases: Kali365; Sneaky 2FA; Storm-2372; Sneaky2FA

Malware/Tools

Forg365, ForgCookie, Kali365, Sneaky 2FA, Gophish, Sneaky2FA, EvilTokens

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources