
Forg365 is a new phishing-as-a-service (PhaaS) platform specializing in stealing Microsoft 365 credentials. It combines adversary-in-the-middle (AiTM) techniques with device code attacks and AI-generated lures to maximize effectiveness. The platform also offers a browser extension for persistent access to compromised accounts without requiring re-authentication.
How Forg365 Operates
Forg365 functions as a cybercriminal toolkit, providing ready-made phishing solutions. Key platform components include:
- Dashboard for creating phishing campaigns
- Integration with Amazon SES and SendGrid for email delivery
- AI content generator for message personalization
- Browser extension for maintaining account access
Technical Infrastructure
The platform leverages legitimate services to mask malicious activity:
| Service | Purpose |
|---|---|
| Amazon SES | Phishing email delivery |
| Cloudflare Pages | Hosting phishing pages |
| SendGrid | Email open tracking |
AI in Forg365 Attacks
The platform's integrated artificial intelligence performs three core functions:
- Generating base phishing email content
- Adapting messages to specific recipients
- Optimizing wording to evade spam filters
How AI Enhances Attack Effectiveness
Using machine learning, the platform analyzes successful campaigns to automatically improve templates by:
- Adapting tone based on victim responses
- Generating personalized subject lines using open-source company data
- Correcting grammatical errors for authenticity
- Incorporating contextual clues from LinkedIn and corporate websites
- Creating text variations for A/B testing
- Analyzing corporate jargon to build trust
- Optimizing send times per recipient
Forg365 Attack Methods
The platform specializes in two primary attack vectors:
Device Code Phishing
Victims see a Microsoft verification code page prompting OAuth 2.0 device code authorization. This method bypasses multi-factor authentication with:
- Persistent account access (up to 90 days)
- No login notifications post-compromise
- Low visibility in security logs
- Automatic token refresh without user knowledge
- Microsoft 365 API access even after password changes
- Geo-restriction bypass via proxy servers
- Privilege escalation through API vulnerabilities
AiTM (Adversary-in-the-Middle)
Classic man-in-the-middle credential interception enhanced with:
- Preconfigured proxy servers for traffic interception
- Perfectly replicated login pages
- CAPTCHA bypass tools
- Automated session cookie collection scripts
- SSL certificate cloning functionality
- Multi-account support for attack distribution
- IP rotation to evade blocks
Defending Against Forg365
Microsoft 365 protection recommendations:
- Restrict device code authentication
- Monitor Microsoft Entra logs for suspicious events
- Review new devices and OAuth grants
- Implement conditional access with geo-restrictions
- Enable device code authentication alerts
- Audit OAuth application permissions regularly
- Limit Microsoft Graph API access for standard users
Advanced Protection Measures
Security experts additionally recommend:
- Enable "High Protection Mode" in Microsoft Defender for Office 365
- Configure conditional access requiring device verification
- Conduct regular security awareness training
- Deploy real-time phishing detection solutions
- Implement user behavior analytics (UEBA)
- Enforce strict session token expiration policies
- Automate compromised credential revocation
- Monitor Microsoft Graph API anomalies
Questions & Answers
How does Forg365 bypass multi-factor authentication?
Through device code flow where victims authorize attacker-controlled devices, granting persistent access without subsequent 2FA prompts because:
- The flow was designed for devices without full browsers
- Tokens automatically refresh after initial authorization
- Most companies don't monitor these events
- Access tokens remain valid despite password changes
- MFA-protected resources remain accessible
- The attack uses legitimate OAuth 2.0 mechanisms
- No interactive confirmation code required
Which companies have been targeted by Forg365?
While specific names aren't public, researchers confirm targets include:
- Financial institutions
- Law firms
- Cloud service providers
- Government agencies
- IT integrators with client system access
- Pharmaceutical companies with research data
- Telecom operators with subscriber information
- Logistics firms managing supply chains
How to check for account compromise?
Review Microsoft 365 Security Center for:
- Suspicious devices and active sessions
- Unexpected mail forwarding rules
- Unknown OAuth applications
- Unusual login activity
- Unauthorized API requests in audit logs
- Security setting changes without authorization
- Conditional access policy modifications
- Anomalous Microsoft Graph API queries
Are alternatives to Microsoft 365 less vulnerable?
Google Workspace and Zoho Workplace have different authentication mechanisms but require independent risk assessments:
| Platform | Device Code Protection | Built-in Phishing Detection | Authentication Customization |
|---|---|---|---|
| Google Workspace | Yes | Advanced Protection Program | High |
| Zoho Workplace | Partial | User Behavior Analytics | Medium |
| Microsoft 365 | Requires manual configuration | Defender for Office 365 | Very High |
How long does Forg365 remain active after detection?
Average lifespan is 3-6 months, but Forg365 demonstrates extended resilience through:
- Legitimate cloud service abuse
- Frequent domain and infrastructure rotation
- Built-in anti-analysis features
- Distributed architecture with backup servers
- Automated host migration processes
- High-reputation domain usage
- Multi-operator support structure
What new Forg365 features are expected?
Researchers anticipate:
- Deepfake audio integration for vishing
- Corporate communication analysis for targeted attacks
- Expansion beyond Microsoft 365 to other SaaS platforms
- User-adaptive phishing site generation
- GPT-powered dynamic victim interactions
- Workflow-based attack automation
- User behavior analysis for optimal timing
- Crypto wallet integration for automated fund transfers