Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts
ID: 541fb7ad-d7eb-5b46-b6e6-8797c80118ca
STIX ID: report--541fb7ad-d7eb-5b46-b6e6-8797c80118ca
Feed Name: GBHackers
Forg365 is a commercial phishing-as-a-service platform marketed via Telegram that targets Microsoft 365 tenants by abusing OAuth device-code flows, employing AiTM techniques, generating AI-tailored lures, and maintaining long-term access through a browser extension called ForgCookie. The report outlines operator tooling and pricing, shows evidence of active use and anti-analysis controls, highlights high-confidence artifacts such as device registrations prefixed with "Forg365-", and recommends blocking device-code flows, monitoring Entra sign-ins and Graph activity, and revoking sessions/refresh tokens after suspected compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
