Forg365 industrializes Microsoft 365 phishing with AI-generated lures

· Source: Computerworld · Field: Technology & Digital — Cybersecurity & Data Privacy, Artificial Intelligence & Machine Learning · Depth: Intermediate, quick

Summary

Forg365 is a newly documented phishing-as-a-service (PhaaS) platform distributed via Telegram, designed to lower the technical barrier for Microsoft 365 account takeovers. It offers automated tools for less-skilled attackers, integrating AI-assisted lure creation with device-code abuse and adversary-in-the-middle techniques to evade authentication and maintain access. Subscriptions are priced at \$400 per month or \$3,800 per year, following a five-day free trial. The platform provides an operator panel for building phishing lures using templates for platforms like DocuSign and SharePoint, managing email delivery, and monitoring compromised mailboxes. Forg365's significance lies in its industrialization of the attacker workflow, including post-compromise tools like the ForgCookie browser extension, which complicates incident response by allowing attackers to retain access even after password resets.

Key takeaway

For CISOs and incident response teams securing Microsoft 365, you must prioritize tightly restricting device-code authentication and deploying phishing-resistant MFA like FIDO2 or WebAuthn. Attackers using platforms like Forg365 can bypass traditional MFA and persist after password resets via stolen refresh tokens. After a compromise, immediately revoke active refresh tokens, terminate sessions, and audit newly registered devices and OAuth permissions to mitigate persistent access.

Key insights

Forg365 industrializes Microsoft 365 phishing through AI-assisted lures and advanced evasion techniques, complicating traditional incident response.

Principles

Method

Forg365's method involves email lures, visitor classification, then device-code phishing or adversary-in-the-middle attacks, followed by post-compromise session persistence and mailbox monitoring.

In practice

Topics

Best for: CTO, Executive, AI Security Engineer, Security Engineer, IT Professional

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Computerworld.