Executive Summary
In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts. Forg365 employs a combination of device code phishing, adversary-in-the-middle (AiTM) tactics, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram, the service costs $400 per month or $3,800 annually. Attackers utilize legitimate email delivery services like Amazon SES and Twilio SendGrid to craft convincing phishing emails, leading victims to Forg365-controlled domains. The platform's operator panel offers features such as AI-generated phishing emails, campaign management, and a browser extension named ForgCookie, which maintains persistent access to compromised accounts by refreshing Microsoft single sign-on cookies.
The emergence of Forg365 underscores the increasing sophistication and accessibility of phishing tools, enabling even low-skilled threat actors to execute complex attacks. This trend highlights the urgent need for organizations to enhance their email security measures, implement robust multi-factor authentication, and educate users about evolving phishing tactics to mitigate the risk of account compromise.
Why This Matters Now
The rise of sophisticated PhaaS platforms like Forg365 lowers the barrier for cybercriminals, increasing the frequency and effectiveness of phishing attacks. Organizations must proactively strengthen their security posture to defend against these evolving threats.
Attack Path Analysis
The Forg365 phishing-as-a-service platform initiates attacks by distributing AI-generated phishing emails that mimic legitimate business communications, leading victims to enter device codes on authentic Microsoft login pages. This grants attackers OAuth tokens, enabling unauthorized access to Microsoft 365 accounts. Once inside, attackers escalate privileges by manipulating OAuth applications and session cookies to maintain persistent access. They then move laterally by accessing additional services like Outlook, Teams, and OneDrive, expanding their foothold within the organization. Command and control are established through continuous monitoring and control of compromised accounts, often using browser extensions to refresh session cookies. Data exfiltration occurs as attackers access and extract sensitive information from emails and cloud storage. The impact includes potential business email compromise, data theft, and financial fraud, severely affecting organizational operations and reputation.
Kill Chain Progression
Initial Compromise
Description
Attackers distribute AI-generated phishing emails that mimic legitimate business communications, leading victims to enter device codes on authentic Microsoft login pages, thereby granting attackers OAuth tokens.
MITRE ATT&CK® Techniques
Phishing for Information
Adversary-in-the-Middle
Obtain Capabilities: Artificial Intelligence
Application Layer Protocol
Email Collection
Phishing
User Execution
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Awareness Training
Control ID: 500.14(b)
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Microsoft 365 phishing attacks threaten customer data, financial transactions, and regulatory compliance through device code manipulation and session theft techniques.
Health Care / Life Sciences
Patient data exposure risk via compromised Microsoft 365 accounts creates HIPAA violations and threatens medical practice operations through phishing campaigns.
Legal Services
Attorney-client privilege and confidential case information vulnerable through Microsoft 365 account takeovers using AI-assisted phishing and session hijacking methods.
Government Administration
Critical government communications and sensitive public data at risk from sophisticated phishing operations targeting Microsoft 365 with antibot evasion capabilities.
Sources
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Thefthttps://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.htmlVerified
- New Forg365 phishing platform uses AI to target Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/Verified
- Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accountshttps://serisec.com/index.php/2026/07/11/forg365-phishing-platform-using-ai-to-attack-microsoft-365-accounts/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is relevant to this incident as it can limit unauthorized access and lateral movement within cloud environments, thereby reducing the attacker's ability to escalate privileges and exfiltrate data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial phishing attack, it could limit the attacker's ability to exploit compromised credentials within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by restricting access to sensitive resources based on strict identity and policy enforcement.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could limit lateral movement by enforcing strict access controls between workloads, thereby reducing the attacker's ability to access additional services.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to maintain command and control by providing real-time monitoring and control over cloud resources.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit data exfiltration by controlling and monitoring outbound traffic, thereby reducing the attacker's ability to extract sensitive information.
Aviatrix Zero Trust CNSF could reduce the overall impact of such attacks by limiting unauthorized access, lateral movement, and data exfiltration, thereby mitigating potential operational and reputational damage.
Impact at a Glance
Affected Business Functions
- Email Communication
- Document Management
- Collaboration Tools
- Cloud Storage
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive corporate emails, confidential documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect anomalous activities.
- • Apply Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors promptly.
- • Enforce strong authentication measures and regularly review OAuth applications to prevent unauthorized access and privilege escalation.



