The Containment Era is here. →Explore

Executive Summary

In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts. Forg365 employs a combination of device code phishing, adversary-in-the-middle (AiTM) tactics, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram, the service costs $400 per month or $3,800 annually. Attackers utilize legitimate email delivery services like Amazon SES and Twilio SendGrid to craft convincing phishing emails, leading victims to Forg365-controlled domains. The platform's operator panel offers features such as AI-generated phishing emails, campaign management, and a browser extension named ForgCookie, which maintains persistent access to compromised accounts by refreshing Microsoft single sign-on cookies.

The emergence of Forg365 underscores the increasing sophistication and accessibility of phishing tools, enabling even low-skilled threat actors to execute complex attacks. This trend highlights the urgent need for organizations to enhance their email security measures, implement robust multi-factor authentication, and educate users about evolving phishing tactics to mitigate the risk of account compromise.

Why This Matters Now

The rise of sophisticated PhaaS platforms like Forg365 lowers the barrier for cybercriminals, increasing the frequency and effectiveness of phishing attacks. Organizations must proactively strengthen their security posture to defend against these evolving threats.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts using advanced techniques like device code phishing and adversary-in-the-middle attacks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is relevant to this incident as it can limit unauthorized access and lateral movement within cloud environments, thereby reducing the attacker's ability to escalate privileges and exfiltrate data.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix CNSF may not prevent the initial phishing attack, it could limit the attacker's ability to exploit compromised credentials within the cloud environment.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by restricting access to sensitive resources based on strict identity and policy enforcement.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security could limit lateral movement by enforcing strict access controls between workloads, thereby reducing the attacker's ability to access additional services.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to maintain command and control by providing real-time monitoring and control over cloud resources.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement could limit data exfiltration by controlling and monitoring outbound traffic, thereby reducing the attacker's ability to extract sensitive information.

Impact (Mitigations)

Aviatrix Zero Trust CNSF could reduce the overall impact of such attacks by limiting unauthorized access, lateral movement, and data exfiltration, thereby mitigating potential operational and reputational damage.

Impact at a Glance

Affected Business Functions

  • Email Communication
  • Document Management
  • Collaboration Tools
  • Cloud Storage
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive corporate emails, confidential documents, and internal communications.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect anomalous activities.
  • Apply Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors promptly.
  • Enforce strong authentication measures and regularly review OAuth applications to prevent unauthorized access and privilege escalation.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image