{"id":1729,"date":"2026-07-13T13:39:29","date_gmt":"2026-07-13T13:39:29","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1729"},"modified":"2026-07-13T13:39:29","modified_gmt":"2026-07-13T13:39:29","slug":"forg365-phaas-targets-microsoft-365-with-device-code-and-aitm-session-theft","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1729","title":{"rendered":"Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjlR-dy6ENZN5NKa1_sViQqXH6fEfEROkwjKV9vTowPmCu_nOALJ89JzGg-ueVJMCAqDHHozMZGd8oWbIlAQDTI8anEd6A2ZK0MdBN_FiShR3UoHGL6Cf0Gbhv8dY9RkVlZxpOCmks29u8Fnmx-JcytGZlnKC_9EuColvIMY4Y5IXH91aRaN5HOgjvvSPEo\/s1700-e365\/ms-device-code1.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A new phishing-as-a-service (PhaaS) operation called <strong>Forg365<\/strong> is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.<\/p>\n<p>Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing lures that make use of legitimate email delivery infrastructure, such as Amazon Simple Email Service (Amazon SES) and Twilio SendGrid, to imitate a redirection chain that blends into regular email traffic before it ends in Forg365-controlled domains.<\/p>\n<p>\u00abThe panel exposes a mature operator workflow: accounts, links, invitations, OAuth app configuration, redirect links, SVG generation, campaign sending, SMTP profiles, SMTP rotation, AI email generation, token vaulting, account intelligence, keyword alerts, viewer links, and browser-extension support,\u00bb ZeroBAC <a href=\"https:\/\/zerobec.com\/blog\/inside-forg365-telegram-distributed-sneaky2fa-style-phaas\" target=\"_blank\">said<\/a>.<\/p>\n<p>The email security company said the PhaaS kit is best understood as similar to the Kali365 (aka Octopi365 and Freedom365) and Sneaky 2FA ecosystem, reflecting the industrialization of the business model, which is now combining bringing together lure creation, delivery, evasion, token\/session handling, and post-compromise operations under a subscription-based setup that allows even threat actors with little-to-no technical expertise to orchestrate phishing campaigns with minimal effort and at scale.<\/p>\n<p>Attack chains using Forg365 have been observed using business document-themed or remittance approval lures to trick recipients into clicking on malicious links. The sender domain uses Amazon SES for delivery, while the message body contains SendGrid-hosted images or tracking resources.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Customers who successfully complete Telegram registration utilize an operator panel accessible over the clearnet (\u00ablogfriend[.]com\/login\u00bb), from where they can generate lures, set up campaigns, and manage captured tokens.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abForg365 includes a device-auth phishing branch that presents a Microsoft-styled verification code page and pushes the victim into a legitimate Microsoft Authentication Broker sign-in flow,\u00bb ZeroBAC explained. \u00abThe victim sees real Microsoft authentication surfaces, but the code authorizes an attacker-controlled session.\u00bb<\/p>\n<p>For AitM phishing, the platform employs route tokens, session cookies, and traffic classification to determine whether to serve phishing content or a benign decoy. If a VPN connection is detected, the kit redirects to innocuous decoy content instead of exposing the phishing pages.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOTm-A07kB-4lDl0mxEhEansYs4m3wMQFiz8iqBJajQgGbf21EJ8kDR6qDMxX8Y1nxOgPx8wbFakbp89yxqVq96oysQ240zu45sVk1Z0soEZHabmcy_KisCgjjP5Jfz5-iejktTBasPI0cEBG606sfhPK2zOJBmA7_Scn-xOov1gxWmK9myfiCHocEVcFn\/s1700-e365\/forg.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOTm-A07kB-4lDl0mxEhEansYs4m3wMQFiz8iqBJajQgGbf21EJ8kDR6qDMxX8Y1nxOgPx8wbFakbp89yxqVq96oysQ240zu45sVk1Z0soEZHabmcy_KisCgjjP5Jfz5-iejktTBasPI0cEBG606sfhPK2zOJBmA7_Scn-xOov1gxWmK9myfiCHocEVcFn\/s1700-e365\/forg.png\" alt=\"\" border=\"0\" data-original-height=\"1231\" data-original-width=\"1959\"\/><\/a><\/div>\n<p>A notable aspect of the Forg365 platform is that it offers an extension named ForgCookie for Chromium-based browsers like Google Chrome, Microsoft Edge, and Brave that is designed for continued access to the compromised accounts. Described as an \u00abautomatic SSO cookie refresh for Microsoft services,\u00bb the add-on acts as an intermediary between the token acquisition and browser access by cycling through the steps listed below &#8211;<\/p>\n<ul>\n<li>Requests account data from the Forg365 backend<\/li>\n<li>Calls the cookie-generation endpoint for a selected account<\/li>\n<li>Clears Microsoft session cookies<\/li>\n<li>Injects the generated refresh-token credential cookie into the Microsoft login domain<\/li>\n<li>Triggers a silent OAuth flow<\/li>\n<li>Captures resulting Microsoft cookies across Microsoft domains<\/li>\n<\/ul>\n<p>Forg365&#8217;s extends beyond simple credential and token harvesting to facilitate a wide array of post-compromise actions, including monitoring for specific keywords in compromised email accounts and drafting a message response to a particular email thread using assistance from AI.<\/p>\n<p>\u00abThe result is a platform that lowers the skill threshold while increasing operational consistency. Less experienced affiliates can use prebuilt templates, while more capable operators can customize landing pages, rotate infrastructure, manage tokens, generate cookie material, and monitor compromised accounts,\u00bb ZeroBAC said.<\/p>\n<p>The disclosure coincides with the discovery of various campaigns that have been found to employ phishing kits for credential theft &#8211;<\/p>\n<ul>\n<li>Sending <a href=\"https:\/\/zerobec.com\/blog\/sneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay\" target=\"_blank\">fake Microsoft account activity alerts<\/a> from a legitimate-but-compromised third-party SaaS sender account to direct users to Sneaky 2FA-style phishing pages to launch a redirection chain that leads to the final phishing host, but not before performing checks to decide whether the visitor is a real user.<\/li>\n<li>Using phishing emails that direct recipients to a website hosted on Canva, which then triggers the device code phishing flow to hijack Microsoft accounts using the <a href=\"https:\/\/www.huntress.com\/blog\/kali365-device-code-phishing-kit\" target=\"_blank\">Kali65 phishing kit<\/a>. The kit supports over 33 different lures, a payout pipeline, and a desktop application called OctoLink Live (aka Kali365 Live) that abuses the stolen token to launch a Chromium browser session and open the victim&#8217;s mailbox in OWA, OneDrive, SharePoint, or admin.microsoft.com. The platform also offers a tool known as OctoLink Sender to mass-send phishing emails from the breached account to other contacts, a technique called lateral phishing.<\/li>\n<li>Phishing campaigns using <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/token-bingo-dont-let-your-code-be-the-winner\/\" target=\"_blank\">Kali365<\/a> have also distributed phishing pages impersonating Russia&#8217;s MAX messenger, indicating an attempt to single out users in Russia. \u00abA phishing operator who can convert MAX account takeovers into propagation has access to one of the largest installed messaging bases in the Russian-speaking world,\u00bb Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger\/\" target=\"_blank\">said<\/a>.<\/li>\n<li>Sending emails mimicking the IRS and Social Security Administration, alongside Adobe, Microsoft, DocuSign, and Dropbox, to deliver legitimate remote access software like ConnectWise ScreenConnect as part of phishing campaigns using a PhaaS kit called <a href=\"https:\/\/socradar.io\/blog\/the-quarry-phaas-irs-ssa-phishing\/\" target=\"_blank\">The Quarry<\/a> that&#8217;s developed, maintained, and sold by a lone operator named RockyBelling. The price of the kit ranges anywhere between $500 and $3,000. This includes tools like Rocky Gmail Sender (a bulk email tool), Rocky Email Sorter (to sort email addresses by domain across Gmail, Yahoo, Hotmail, and AOL), and VioletRAT.<\/li>\n<li>Sending <a href=\"https:\/\/censys.com\/blog\/following-a-usps-smishing-kit-through-censys-dns-data\/\" target=\"_blank\">SMS messages<\/a> impersonating the U.S. Postal Service (USPS) and UPS to trick victims into visiting a phishing page that prompts users to enter their personal and financial information under the pretext of a failed package delivery and scheduling a new delivery. \u00abUnderneath the deception, the kit captures data in real time,\u00bb Censys said. \u00abIt opens a WebSocket back to its origin and streams the victim\u2019s card data keystroke-by-keystroke, runs a server-side BIN lookup on the card number, and pushes routing decisions (retry, PIN prompt, OTP prompt, kill-switch) back into the victim&#8217;s browser while they type.\u00bb<\/li>\n<li>Using fake bid proposal workflows to take over Google accounts using a framework called <a href=\"https:\/\/zerobec.com\/blog\/nyasher-google-account-takeover-webflow-cloudflare-workers\" target=\"_blank\">Nyasher<\/a>. The redirection chain incorporates a \u00abpress-and-hold\u00bb verification page to filter out automated scanners and bots, before navigating to a blob URL. \u00abThe final page displayed a Google sign-in interface but was not reachable as a normal hosted HTML document,\u00bb ZeroBAC said. \u00abIt existed as a browser-created object URL.\u00bb<\/li>\n<li>Using bogus Google Partners and Google Premier Partner enrollment workflows in phishing emails to redirect recipients to a fake Google sign-in page designed to capture credentials in real time as part of a campaign codenamed <a href=\"https:\/\/zerobec.com\/blog\/gppstorm-google-partners-phishing-workspace-credentials\" target=\"_blank\">GPPStorm<\/a>.<\/li>\n<li>Using a legacy email alias to target a user&#8217;s inbox and launch a device code phishing flow that uses the EvilTokens kit. \u00abThe kit was reached through a Mailjet tracking link, then a compromised WordPress site, then a CAPTCHA interstitial, then the Cloudflare Workers host,\u00bb ZeroBAC <a href=\"https:\/\/zerobec.com\/blog\/eviltokens-device-code-phishing-legacy-aliases\" target=\"_blank\">said<\/a>. \u00abThree live infrastructure hops between the email body and the kit, none of which is the kit itself.\u00bb<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBxLQDy7VdLze43eMmpRllTXaPKPfB_veNUxQlqIu3-68GBJtegkhDGCqtaiSymOQviROdxln1FSd4zdMp5Jv9jeF1xQxLPc9uo9H7zW2nWHNax0wT0Y8JRj-zyUfbaCLqhxSfQT2sCfhWMBPL6UVgsh5RYVNVxwus_mW_BY9Ptwz3z7iF0_LWOnte-gqg\/s1600\/sy-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>To counter these threats, it&#8217;s recommended to block device code authentication unless it&#8217;s required, review mailbox artifacts after device code events for any signs of unusual activity, audit mail-flow rules, and decommission legacy aliases that no longer correspond to active employees.<\/p>\n<p>\u00abThe campaign succeeded in reaching the inbox because the recipient organization still maintained an active forwarding relationship from a pre-acquisition namespace into a current mailbox,\u00bb ZeroBAC noted. <\/p>\n<p>\u00abThe attacker used a still-resolvable historical identity to deliver mail that, from the SEG&#8217;s point of view, looked like normal forwarded correspondence. From the user&#8217;s point of view, the message landed in their working inbox with no visible cue that it had taken an indirect path.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1730,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[392,10,539,2497,147,2498,1161,78,526],"class_list":["post-1729","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aitm","tag-code","tag-device","tag-forg365","tag-microsoft","tag-phaas","tag-session","tag-targets","tag-theft"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1729"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1729\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1730"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}