Forg365: the new phishing kit built to hoover up Microsoft 365 logins

A fresh phishing-as-a-service operation uses AI to write the bait and a browser extension to keep the door open long after the theft.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: an anonymous office desk at dusk, a laptop screen glowing with an out-of-focus generic corporate sign-in page
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers at ZeroBEC disclosed a new phishing-as-a-service platform called Forg365 that targets Microsoft 365 accounts.
  • Forg365 bundles AI-written lures, two account-stealing techniques, and a browser extension that keeps stolen access alive.
  • The kit delivers emails through Amazon SES and hosts fake login pages on Cloudflare Pages to look legitimate.
  • ZeroBEC recommends disabling Microsoft's device-code sign-in unless it's genuinely needed.

There's a new criminal service on the market, aimed squarely at your work email.

It's called Forg365. Security researchers at ZeroBEC, an email security company, describe it as a phishing-as-a-service platform: a ready-made toolkit that lets less skilled criminals run professional-grade attacks by the month, the way anyone might rent software. Its target is Microsoft 365, the Outlook and SharePoint logins used by most offices. The operation was first reported by BleepingComputer, and the tactics are unusually polished. We've tracked the adversary-in-the-middle phishing technique since our first coverage on 9 June 2026, and Forg365 combines it with a newer trick in a single platform.

How does the scam actually work?

It starts with an email dressed as a business document. An AI assistant built into the criminal's control panel writes or refines the text, so the grammar is clean and the tone matches a real company. Operators craft the lure, prepare the copy, and launch the attack from the same dashboard.

Emails go out through Amazon SES, a legitimate Amazon email service, and images inside them load from SendGrid, a mainstream marketing tool. That combination helps messages slip past spam filters. Click the link, and you land on a fake Microsoft sign-in page hosted on Cloudflare Pages.

From there, Forg365 offers two attack paths. The first is adversary-in-the-middle phishing, where the fake page quietly relays your credentials to the real Microsoft site while capturing the session cookie, the small file your browser uses to prove you're logged in. Criminals load that cookie into their own browser and walk straight in.

The second is device-code phishing. Microsoft has a legitimate sign-in flow for gadgets that can't display a proper login screen, such as smart TVs or IoT appliances. Forg365 abuses it by showing victims a real Microsoft code page and prompting them to enter a code that actually authorises the attacker's device, not their own.

What makes this one different?

Two things stand out.

One is the AI integration. Custom phishing lures used to take real effort. Now the operator types a prompt inside the same panel they use to manage stolen accounts, and the email appears seconds later. As ZeroBEC put it, "AI reduces the cost of developing custom phishing content, but it also reduces the cost of building custom PhaaS platforms."

The other is ForgCookie, a browser extension that runs in Chrome and Edge. Once the criminals have your session, ForgCookie silently requests fresh account data from the Forg365 backend, clears existing cookies, and triggers a background OAuth flow to capture new ones. That's persistent access without ever asking you to log in again.

The kit also scans hijacked mailboxes for keywords the attacker picks, say "wire transfer", and alerts the operator when a match appears. To keep researchers out, an antibot feature redirects anyone arriving via VPN or automated tools to harmless content.

For context: our 3 July story on the ARToken kit found more than 80 hidden commands inside a rival Microsoft 365 phishing platform. Forg365 isn't hiding its features; it's selling them openly as a monthly service. That shift matters more than any single technical trick.

Should you worry?

If you use Microsoft 365 at work, treat any email asking you to enter a verification code on a Microsoft page with suspicion. A real device setup doesn't arrive unsolicited in your inbox.

For account administrators, ZeroBEC's advice is practical. Disable device-code sign-in unless your organisation actually needs it. Watch Microsoft Entra logs for device-code events, unexpected new device registrations, and unusual OAuth app approvals, including mailbox rules and Microsoft Authentication Broker activity.

If you suspect a compromise, revoke every active session and token immediately. A stolen cookie is only useful while it's still valid.

© 2026 Threat Vectr