logo

Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts

ID: 541fb7ad-d7eb-5b46-b6e6-8797c80118ca

STIX ID: report--541fb7ad-d7eb-5b46-b6e6-8797c80118ca

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Divya

...
...

Forg365 is a commercial phishing-as-a-service platform marketed via Telegram that targets Microsoft 365 tenants by abusing OAuth device-code flows, employing AiTM techniques, generating AI-tailored lures, and maintaining long-term access through a browser extension called ForgCookie. The report outlines operator tooling and pricing, shows evidence of active use and anti-analysis controls, highlights high-confidence artifacts such as device registrations prefixed with "Forg365-", and recommends blocking device-code flows, monitoring Entra sign-ins and Graph activity, and revoking sessions/refresh tokens after suspected compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.