Forg365: when phishing becomes a monthly subscription

On 18 June we published an analysis of EvilTokens: the technique that steals Microsoft 365 sessions without touching the password, abusing Microsoft's legitimate device authentication flow. If you have not read it, that is the starting point for understanding what comes next.

This week, researchers at ZeroBEC have documented Forg365. It uses exactly the same technique. But Forg365 is not an attack — it is a platform. And that difference changes everything.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

From technique to product

EvilTokens was a tool in the hands of specialist groups. Forg365 is a subscription service distributed via Telegram, complete with a control panel, technical support, updates and a fixed price. Anyone with a budget — and no technical knowledge whatsoever — can purchase access, configure a campaign and launch it in minutes.

This has a name in cybersecurity: Phishing-as-a-Service (PhaaS). The organised crime business model applied to digital fraud. The attacker does not need to build anything — just pay and operate.

What the subscription includes

Forg365's panel integrates everything an attacker needs to steal and maintain access to Microsoft 365 accounts in a single environment:

Why MFA is still not enough

Like EvilTokens, Forg365 does not need the password. It does not need to defeat two-factor authentication. It tricks the victim into completing the authentication process on the attacker's behalf — and once the session token is obtained, ForgCookie ensures that access never expires.

The result is that "we have MFA enabled" continues to be an incomplete answer. What protects against this type of attack is not an additional authentication layer but the ability to detect that something unusual is happening in session logs before the damage becomes irreversible.

What has changed

A year ago, an attack of this level required advanced technical knowledge, dedicated infrastructure and development time. Today it requires a Telegram account and a budget.

AI has removed the last barrier that limited this type of fraud: the creation of convincing lures. Previously, a poorly written phishing email with spelling mistakes was the most reliable signal for detecting the deception. Now, AI generates personalised, well-written messages adapted to each victim's professional context, at machine speed and at near-zero marginal cost.

Phishing is no longer artisanal. It is industrial.

What to do if your organisation uses Microsoft 365

Do you suspect a corporate account has been compromised or have you detected unusual activity in Microsoft 365 logs? Oscar Orts — court-certified IT expert — can forensically analyse the incident and produce an expert report with full legal validity for judicial proceedings or insurance claims.