Forg365 phishing service targets Microsoft 365 accounts with device-code login tricks and cookie-stealing browser extension

Researchers identified a phishing-as-a-service platform called Forg365 that is built to steal Microsoft 365 accounts and keep access to them after login. The service combines OAuth device-code phishing and adversary-in-the-middle (a login proxy that captures session tokens), uses AI inside its operator dashboard to generate lures, and includes a Chrome-, Edge-, and Brave-compatible extension called ForgCookie that refreshes stolen Microsoft single sign-on cookies for persistent access.
Why it matters: Microsoft 365 users and administrators should treat this as an active account-takeover threat, especially because it abuses legitimate Microsoft authentication flows instead of only stealing passwords. Organizations should harden device-code and OAuth app controls, review suspicious consent grants and session tokens, and warn users not to enter Microsoft verification codes from unsolicited emails.

Sources

New Forg365 phishing platform uses AI to target Microsoft 365 accounts
Bill Toulas 2026.07.09 100% relevant
This article establishes a distinct new phishing platform, Forg365, with its own infrastructure, attack methods, and post-compromise browser extension; it is not the same underlying event as the separately tracked Kali365 campaign.
← Back to all stories