Forg365 industrializes Microsoft 365 phishing with AI-generated lures
Summary
Forg365 is a newly documented phishing-as-a-service (PhaaS) platform distributed via Telegram, designed to lower the technical barrier for Microsoft 365 account takeovers. It offers automated tools for less-skilled attackers, integrating AI-assisted lure creation with device-code abuse and adversary-in-the-middle techniques to evade authentication and maintain access. Subscriptions are priced at \$400 per month or \$3,800 per year, following a five-day free trial. The platform provides an operator panel for building phishing lures using templates for platforms like DocuSign and SharePoint, managing email delivery, and monitoring compromised mailboxes. Forg365's significance lies in its industrialization of the attacker workflow, including post-compromise tools like the ForgCookie browser extension, which complicates incident response by allowing attackers to retain access even after password resets.
Key takeaway
For CISOs and incident response teams securing Microsoft 365, you must prioritize tightly restricting device-code authentication and deploying phishing-resistant MFA like FIDO2 or WebAuthn. Attackers using platforms like Forg365 can bypass traditional MFA and persist after password resets via stolen refresh tokens. After a compromise, immediately revoke active refresh tokens, terminate sessions, and audit newly registered devices and OAuth permissions to mitigate persistent access.
Key insights
Forg365 industrializes Microsoft 365 phishing through AI-assisted lures and advanced evasion techniques, complicating traditional incident response.
Principles
- Phishing-as-a-service platforms are evolving with AI.
- Device-code authentication is a significant attack vector.
- Stolen refresh tokens enable persistent access.
Method
Forg365's method involves email lures, visitor classification, then device-code phishing or adversary-in-the-middle attacks, followed by post-compromise session persistence and mailbox monitoring.
In practice
- Block device-code authentication in Microsoft Entra ID.
- Deploy phishing-resistant MFA like FIDO2/WebAuthn.
- Revoke active refresh tokens post-compromise.
Topics
- Forg365
- Phishing-as-a-Service
- Microsoft 365 Security
- AI-Assisted Phishing
- Device-Code Phishing
- Incident Response
Best for: CTO, Executive, AI Security Engineer, Security Engineer, IT Professional
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Computerworld.