Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
15:03 · July 13, 2026 · Hacker News AI Section

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing
Summary
A new phishing-as-a-service platform called Forg365 targets Microsoft 365 accounts through device-code flows and adversary-in-the-middle interception. Operators subscribe via Telegram for $400 per month or $3,800 annually and receive access to a control panel at logfriend[.]com that handles lure generation, campaign delivery, token storage, and post-compromise mailbox management. The service combines legitimate delivery channels such as Amazon SES and Twilio SendGrid with SVG-based redirects and antibot logic that serves benign content when a VPN is detected.
Device-code phishing presents a Microsoft-branded verification page that initiates a genuine authentication-broker session; once the victim completes the flow, the resulting token authorizes an attacker-controlled session. Adversary-in-the-middle capabilities rely on route tokens and session cookies to classify traffic and maintain persistence. A companion Chromium extension, ForgCookie, automatically refreshes single-sign-on cookies for Microsoft services, extending access beyond initial token capture.
The platform also supplies AI-assisted tools for crafting initial lures and for drafting replies to specific email threads once an account is compromised. Keyword monitoring inside captured mailboxes further automates follow-on activity. These features mirror earlier kits such as Kali365 and Sneaky 2FA, illustrating the continued industrialization of phishing operations that bundle infrastructure, evasion, and post-exploitation under a single subscription.
Defensive measures include disabling device-code authentication where it is not required, reviewing mailbox artifacts after any device-code sign-in events, auditing mail-flow rules, and removing legacy forwarding aliases that no longer map to active users. One observed campaign succeeded because an outdated pre-acquisition namespace still forwarded mail into an active inbox, bypassing external filters without visible indicators to the recipient.
Why it matters
This article highlights the weaponization of AI by cybercriminals to scale and enhance phishing attacks against widely used enterprise platforms like Microsoft 365. It provides actionable threat intelligence and mitigation strategies crucial for Dutch security professionals defending corporate networks against AI-augmented threats.






