Forg365: when phishing becomes a monthly subscription
On 18 June we published an analysis of EvilTokens: the technique that steals Microsoft 365 sessions without touching the password, abusing Microsoft's legitimate device authentication flow. If you have not read it, that is the starting point for understanding what comes next.
This week, researchers at ZeroBEC have documented Forg365. It uses exactly the same technique. But Forg365 is not an attack — it is a platform. And that difference changes everything.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
From technique to product
EvilTokens was a tool in the hands of specialist groups. Forg365 is a subscription service distributed via Telegram, complete with a control panel, technical support, updates and a fixed price. Anyone with a budget — and no technical knowledge whatsoever — can purchase access, configure a campaign and launch it in minutes.
This has a name in cybersecurity: Phishing-as-a-Service (PhaaS). The organised crime business model applied to digital fraud. The attacker does not need to build anything — just pay and operate.
What the subscription includes
Forg365's panel integrates everything an attacker needs to steal and maintain access to Microsoft 365 accounts in a single environment:
- AI-assisted lure generation: the operator describes the target and the AI generates a personalised phishing email from within the same panel. Invoices, shared documents, calendar invitations, SharePoint requests — all tailored to the victim's role and industry.
- Two combined attack methods: device code phishing (the same mechanism as EvilTokens) and AiTM (adversary-in-the-middle), which intercepts session cookies during a normal authentication.
- ForgCookie: a browser extension compatible with Chrome, Edge and Brave that automatically refreshes Microsoft SSO cookies. Once the account is compromised, the attacker maintains access indefinitely without needing to re-authenticate.
- Post-compromise intelligence panel: includes keyword monitoring across compromised mailboxes — the attacker sets alerts for terms such as "transfer", "password" or "invoice" and receives a notification every time they appear in the victim's email.
- AntiBot: the system detects researchers, sandboxes and analysis tools, serving them harmless content to avoid being studied.
Why MFA is still not enough
Like EvilTokens, Forg365 does not need the password. It does not need to defeat two-factor authentication. It tricks the victim into completing the authentication process on the attacker's behalf — and once the session token is obtained, ForgCookie ensures that access never expires.
The result is that "we have MFA enabled" continues to be an incomplete answer. What protects against this type of attack is not an additional authentication layer but the ability to detect that something unusual is happening in session logs before the damage becomes irreversible.
What has changed
A year ago, an attack of this level required advanced technical knowledge, dedicated infrastructure and development time. Today it requires a Telegram account and a budget.
AI has removed the last barrier that limited this type of fraud: the creation of convincing lures. Previously, a poorly written phishing email with spelling mistakes was the most reliable signal for detecting the deception. Now, AI generates personalised, well-written messages adapted to each victim's professional context, at machine speed and at near-zero marginal cost.
Phishing is no longer artisanal. It is industrial.
What to do if your organisation uses Microsoft 365
- Review whether the device code authentication flow is enabled. If it is not actively used, disable it — it is the primary attack vector here.
- Monitor Microsoft Entra logs for unexpected device-code authentication events, newly registered devices and unrecognised OAuth grants.
- If compromise is suspected: revoke all active tokens and sessions immediately, review inbox rules (attackers typically create rules to redirect or delete emails) and temporarily disable the affected account.
- Train employees specifically on this pattern: if they are ever asked to enter a device code without having initiated the process themselves, they should stop and report it immediately.
Do you suspect a corporate account has been compromised or have you detected unusual activity in Microsoft 365 logs? Oscar Orts — court-certified IT expert — can forensically analyse the incident and produce an expert report with full legal validity for judicial proceedings or insurance claims.