Executive Summary
In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code phishing techniques with AI-assisted lure generation. The platform offers a browser extension that maintains access to compromised accounts without re-authentication. Researchers at ZeroBEC identified features in Forg365 similar to those in other PhaaS platforms like Kali365 and Sneaky2FA, indicating a sophisticated operation capable of blending malicious activities into regular email traffic.
The integration of AI in Forg365's dashboard allows attackers to craft and refine phishing emails efficiently, reducing the cost and complexity of developing custom phishing content. This advancement underscores the evolving threat landscape, where AI is increasingly leveraged to enhance the effectiveness and accessibility of cyberattacks, posing significant challenges to traditional security measures.
Why This Matters Now
The emergence of Forg365 highlights the growing sophistication of phishing attacks, utilizing AI to automate and enhance malicious campaigns. Organizations must adapt their security strategies to counteract these advanced threats, emphasizing the need for continuous monitoring and user education to recognize and respond to such attacks effectively.
Attack Path Analysis
The Forg365 phishing platform initiates attacks by sending AI-generated phishing emails that impersonate trusted services, leading victims to enter device codes on legitimate Microsoft pages. This grants attackers access tokens, allowing them to bypass multi-factor authentication and gain unauthorized access to Microsoft 365 accounts. Once inside, attackers can escalate privileges by exploiting OAuth permissions, enabling broader access within the victim's environment. They may then move laterally by accessing other services linked to the compromised account. Command and control are maintained through persistent access facilitated by browser extensions like ForgCookie, which refresh session cookies. Attackers can exfiltrate sensitive data stored in Microsoft 365 services such as Outlook, Teams, and OneDrive. The impact includes unauthorized data access, potential data theft, and further exploitation of compromised accounts.
Kill Chain Progression
Initial Compromise
Description
Attackers send AI-generated phishing emails impersonating trusted services, leading victims to enter device codes on legitimate Microsoft pages, granting attackers access tokens.
MITRE ATT&CK® Techniques
Spearphishing Link
Use Alternate Authentication Material: Application Access Token
Valid Accounts: Cloud Accounts
Email Collection: Remote Email Collection
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing cryptographic keys are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication and authorization mechanisms.
Control ID: Identity Pillar: Authentication and Authorization
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value Microsoft 365 environments face AI-enhanced phishing targeting authentication tokens, bypassing MFA through device-code flows, enabling persistent account access and data exfiltration.
Health Care / Life Sciences
HIPAA-regulated organizations risk patient data exposure through compromised Microsoft 365 accounts, with automated cookie refresh enabling prolonged unauthorized access to sensitive healthcare information.
Government Administration
Critical government Microsoft 365 infrastructure vulnerable to sophisticated PhaaS operations using legitimate AWS/Cloudflare services, potentially compromising classified communications and administrative systems.
Legal Services
Law firms face attorney-client privilege breaches through AI-crafted phishing targeting Microsoft 365, with keyword monitoring capabilities scanning compromised mailboxes for sensitive legal terms.
Sources
- New Forg365 phishing platform uses AI to target Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/Verified
- Inside Forg365: Telegram-Distributed Sneaky2FA-Style PhaaShttps://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaasVerified
- FBI warns of Kali365 phishing service targeting Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial phishing attack, it would likely limit the attacker's ability to exploit compromised credentials to access other workloads within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by restricting access to sensitive resources based on strict identity verification.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to maintain persistent access by monitoring and controlling unauthorized communications across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate sensitive data by enforcing strict outbound traffic policies.
Aviatrix CNSF would likely reduce the overall impact of the attack by limiting the attacker's ability to access and exploit sensitive data across the cloud environment.
Impact at a Glance
Affected Business Functions
- Email Communication
- Document Management
- Collaboration Tools
- Cloud Storage
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive corporate emails, confidential documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities.
- • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and enforcement.
- • Regularly review and update security policies to address evolving phishing tactics.



