News·4 min read

Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions

A newly identified phishing-as-a-service (PhaaS) platform, Forg365, is abusing Microsoft’s device code authentication flow to hijack Microsoft 365 sessions at scale. ZeroBEC researchers uncovere

CS
CyberShield Team
2026-07-10
Share:
Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions

A newly identified phishing-as-a-service (PhaaS) platform, Forg365, is abusing Microsoft’s device code authentication flow to hijack Microsoft 365 sessions at scale. ZeroBEC researchers uncovered the platform after tracing a business-document-themed phishing email back to a fully productized operator panel that offered AI-generated lures, token theft, and persistent session access as a subscription service. Forg365 operates […] The post Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions appeared first on Cyber Security News.

A newly identified phishing-as-a-service (PhaaS) platform, Forg365, is abusing Microsoft’s device code authentication flow to hijack Microsoft 365 sessions at scale. ZeroBEC researchers uncovered the platform after tracing a business-document-themed phishing email back to a fully productized operator panel that offered AI-generated lures, token theft, and persistent session access as a subscription service. Forg365 operates on a SaaS-style business model, distributed entirely via Telegram, with onboarding, support, and payment coordination handled directly through its channels. Forg365 PhaaS Abuses Microsoft Device-Code Flow ZeroBEC team observed a 5-day free trial, monthly access priced at $400, and annual subscriptions at $3,800, which positions Forg365 as a maintained commercial service rather than a disposable phishing kit. Phishing mail (Source: zerobec) This mirrors the distribution pattern seen with Kali365, a similar PhaaS platform flagged by the FBI’s IC3 in a May 2026 advisory for capturing Microsoft 365 OAuth tokens via Telegram-distributed kits. The primary operator panel, hosted at logfriend[.]com, exposes a mature toolset including OAuth app configuration, SMTP rotation, AI-assisted email generation, and a Token Vault for managing stolen credentials. The platform supports two distinct attack branches. The device-auth branch displays a Microsoft-styled verification code and redirects victims into the legitimate Microsoft Authentication Broker flow, tricking users into authorizing attacker-controlled sessions without ever revealing a password, a technique that has become increasingly common across PhaaS kits like EvilTokens and Kali365 since early 2026. Microsoft Authentication Broker sign-in page (Source: zerobec) The AiTM branch instead uses route tokens and session cookies to intercept credentials directly, with built-in traffic classification that redirects VPN users to a benign decoy page to evade automated analysis. A companion browser extension, ForgCookie, refreshes Microsoft SSO cookies to maintain persistent access without re-authentication, effectively surviving password resets by replaying refresh tokens. Microsoft Entra telemetry linked campaign activity to a Comcast/Xfinity residential IP address during device code authorization, then to a Forg365 backend hosted in Kyiv, Ukraine, which performed Microsoft Graph and device registration activity. Compromised tenants showed Entra-joined devices with Forg365-prefixed names, a marker that researchers note aligns with a broader pattern in which attackers using these kits often leave default or predictable device names, making detection somewhat easier for defenders who actively monitor new device registrations. Forg365 operating model (Source: zerobec) The delivery chain also abused legitimate services, including Amazon SES and SendGrid, to blend phishing emails into normal SaaS traffic before redirecting victims through Cloudflare-hosted landing pages and a Gophish-based sending component. Zerobec stated that Microsoft already classifies device-code flow as a high-risk authentication method precisely because it can be abused in phishing attacks like this one. Forg365 shows why: the victim interacts with genuine Microsoft authentication surfaces while unknowingly authorizing attacker access, and the platform then works to preserve that access through token, cookie, and inbox workflows. The case also demonstrates that AI is now embedded directly into PhaaS operator panels, lowering the technical barrier for less-skilled affiliates while giving advanced operators granular control over token capture and mailbox monitoring. Mitigation Security teams should: Block or restrict device-code authentication via Conditional Access unless explicitly required Monitor Entra sign-in logs for originalTransferMethod=deviceCodeFlow paired with unusual device registrations Hunt for device names prefixed with “Forg365-“ Forg365 illustrates a broader trend: PhaaS platforms are evolving from simple credential-harvesting kits into full-featured, AI-enhanced identity-attack ecosystems that sustain long-term access well beyond the initial phish. Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google. The post Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.