Researchers identified a phishing-as-a-service platform called Forg365 that is built to steal Microsoft 365 accounts and keep access to them after login. The service combines OAuth device-code phishing and adversary-in-the-middle (a login proxy that captures session tokens), uses AI inside its operator dashboard to generate lures, and includes a Chrome-, Edge-, and Brave-compatible extension called ForgCookie that refreshes stolen Microsoft single sign-on cookies for persistent access.
Why it matters: Microsoft 365 users and administrators should treat this as an active account-takeover threat, especially because it abuses legitimate Microsoft authentication flows instead of only stealing passwords. Organizations should harden device-code and OAuth app controls, review suspicious consent grants and session tokens, and warn users not to enter Microsoft verification codes from unsolicited emails.
Bill Toulas
2026.07.09
100% relevant
This article establishes a distinct new phishing platform, Forg365, with its own infrastructure, attack methods, and post-compromise browser extension; it is not the same underlying event as the separately tracked Kali365 campaign.
← Back to all stories