Forg365 PhaaS Employs Advanced Phishing Techniques to Target Microsoft 365 Accounts

Forg365 is a new phishing-as-a-service operation that targets Microsoft 365 users by combining device code phishing, adversary-in-the-middle tactics, and AI-generated phishing lures. The service is sold on Telegram and incorporates advanced evasion techniques alongside post-compromise mailbox exploitation.
What happened
Security researchers have identified Forg365, a novel phishing-as-a-service (PhaaS) platform, that specializes in attacks against Microsoft 365 accounts. The service employs device code phishing and adversary-in-the-middle (AitM) methods to intercept authentication tokens and credentials. It also uses antibot evasion techniques and artificial intelligence to craft convincing phishing lures.
Forg365 operates as a subscription-based service on Telegram, offering access for $400 per month or $3,800 annually. The threat actors behind Forg365 also conduct post-compromise operations within victim mailboxes, enabling prolonged access and potential data exfiltration or further attacks.
Why it matters
Microsoft 365 is widely used across businesses and organizations worldwide, making it a significant target for phishing attacks. Forg365's use of sophisticated phishing techniques, such as device code phishing and AitM session theft, poses a heightened risk to account security.
Moreover, the integration of AI-generated phishing lures may increase the likelihood of successful credential capturing by crafting more convincing and personalized phishing messages. The availability of this capability as a service lowers the barrier for threat actors to launch targeted phishing campaigns at scale.
What security teams should do
Security teams should prioritize monitoring for signs of device code phishing and AitM interception attacks, particularly within Microsoft 365 environments. Ensuring multi-factor authentication (MFA) is enforced can mitigate risks from credential theft.
Teams should also be vigilant for suspicious mailbox activity that might indicate post-compromise operations. Reviewing and restricting Telegram-based threat intelligence feeds may help detect and block Forg365-related infrastructure or indicators of compromise.
Key technical details
Forg365 combines multiple advanced attack techniques including device code phishing, which involves tricking users into approving device authentication codes. It also uses adversary-in-the-middle (AitM) tactics to capture session tokens during authentication flows.
The service incorporates antibot technology to evade automated detection systems and employs AI tools to automatically generate phishing lures designed to improve user click rates. Once accounts are compromised, Forg365 operators access mailboxes to conduct further malicious activities.
Affected organizations/products
The operation specifically targets Microsoft 365 accounts. The phishing chains are distributed through Telegram as a subscription phishing-as-a-service offering.
Source attribution
https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html