A newly identified phishing service, Forg365, is reshaping the landscape of Microsoft 365 security by offering tools that lower the barrier for less experienced attackers. Provided via Telegram, this phishing-as-a-service model equips users with automated techniques to bypass traditional authentication measures and maintain access even after initial account compromise.
Research from cybersecurity firm ZeroBEC reveals that Forg365 leverages AI to create convincing phishing lures, exploit device codes, and implement adversary-in-the-middle strategies. The service is marketed with a five-day trial and offers subscription plans of $400 per month or $3,800 annually.
Users of Forg365 can craft phishing schemes from a centralized control panel, manage intercepted account data, and oversee compromised Microsoft 365 mailboxes. The platform includes template designs that impersonate popular business services like DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive, which increases the likelihood of successful attacks.
Jonathan Ong, senior analyst at Omdia, highlighted the critical factor of AI integration within Forg365, stating, “The degree to which AI is incorporated into Forg365 and empowers users is what makes it concerning.” This automation signifies a concerning trend in the professionalization of phishing operations.
Understanding Forg365's Mechanism
The phishing campaigns analyzed by ZeroBEC typically start with emails masquerading as requests for business document approvals, directing recipients through a series of legitimate cloud and email services via redirects.
Forg365 intelligently assesses incoming traffic to decide on the appropriate phishing tactic, whether that's displaying a device-code phishing page, launching an adversary-in-the-middle attack, or redirecting users to a harmless decoy.
In device-code attacks, victims are led to what appears to be a legitimate Microsoft authentication process, encouraging them to input a code that grants the attacker access to their session. This strategy exploits authentic Microsoft infrastructure, making it seem trustworthy.
The platform can also initiate relayed authentication through adversary-in-the-middle attacks, capturing vital session data. To remain undetected, suspicious visitors are redirected to a safe page, thus obscuring the phishing operation from security research and automated defenses.
Challenges in Incident Response
Forg365 enhances attack capabilities through a browser extension known as ForgCookie, which enables attackers to generate and refresh Microsoft single sign-on cookies using their own browsers. This facility complicates incident response efforts significantly, allowing attackers to retain access even after a password change.
Forg365 also includes tools for maintaining active sessions and monitoring compromised inboxes, with the capability for attackers to share read-only access to mailboxes via password-protected links.
As a result, even standard password resets may not disrupt an attacker’s ability to access an account, as refreshed tokens or established sessions remain valid. Security teams must also scrutinize any devices registered during a breach.
According to cybersecurity planner Devashri Datta, Chief Information Security Officers (CISOs) should prioritize dual controls: strictly limiting device-code authentication while also implementing phishing-resistant MFA methods such as FIDO2 or WebAuthn.
Organizations without device-code authentication should consider disabling it in Microsoft Entra ID to disrupt Forg365's reliance on this approach, although it won’t safeguard against all attack techniques employed by Forg365.
Entities still leveraging device-code authentication must pinpoint legitimate uses before instituting broader restrictions, ensuring that necessary exceptions exist for essential tools.
Implementing more secure authentication solutions may necessitate new hardware setups or managed mobile devices, potentially leading to a spike in support requests during this transition, according to Datta.
After a compromise, incident response teams should revoke active refresh tokens and terminate sessions. Experts recommend reviewing and revoking unauthorized OAuth permissions, specifically monitoring for unusual Microsoft Graph activity linked with unknown sources.
Additionally, any mailbox forwarding rules or delegated access should be audited for unauthorized modifications, as these changes could enable attackers to remain informed of communications even after a password has been reset.
Datta further emphasizes that teams must audit new devices registered during an incident and remove those not tied to legitimate user activities. Addressing the presence of any unauthorized authenticator applications introduced during the breach is critical.
Interestingly, ZeroBEC identified devices linked to their investigation that bore names starting with “Forg365.” This detail could serve as a useful indicator of compromise for defense teams in the field.