Forg365 Makes M365 Takeovers “Phishing for Dummies”

CSO Online · High sophistication
Last updated July 30, 2026

Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using convincing document-themed lures. It uses device-code phishing and adversary-in-the-middle methods to get access, and adds tooling (including a cookie-refresh browser extension) that can let attackers keep access even after a password reset.

How the attack worked

The campaign began with an email built around a business-document and remittance-approval pretext, a theme designed to create urgency for finance and accounts payable staff. The message relied on legitimate cloud and email services before routing recipients through several redirects, eventually reaching either a device-code phishing page or an adversary-in-the-middle flow. Forg365, the underlying phishing-as-a-service platform, classified visitors before deciding which page to show, and suspicious visitors were diverted to a benign decoy page to help conceal the phishing flow from researchers and automated security tools.

In the device-code variant, the victim is directed to a legitimate Microsoft authentication process and persuaded to enter a code that authorizes a session controlled by the attacker. Because the flow uses genuine Microsoft infrastructure, the request can appear credible even to attentive users. A companion browser extension, described in the reporting as ForgCookie, helps attackers generate or refresh Microsoft SSO cookies, which means access can persist after a password reset.

Why it succeeded

Several factors made this approach effective:

  • The service includes templates that impersonate widely used business platforms such as DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive, making the lure familiar to knowledge workers.
  • The device-code method borrows real Microsoft sign-in infrastructure, so victims are not asked to enter credentials on an obviously fake site.
  • Decoy pages and visitor classification helped operators avoid detection by researchers and security tooling.
  • The cookie-refresh capability meant that a password reset alone did not remove attacker access.

What to watch for

Defenders and employees should treat the following as red flags:

  • Unexpected remittance or document-approval requests that create urgency to act quickly.
  • Multiple redirects before landing on a Microsoft sign-in page.
  • Any request to enter a device code to “approve” a document, which is unusual for normal workflows.
  • Repeated or unexplained sign-ins shortly after interacting with a suspicious message.

Building resistance

Organizations can reduce risk with a mix of awareness and technical response steps. Staff should be trained to treat unexpected document or signature emails as high-risk and verify requests through a known channel before clicking, and to stop and report any prompt asking them to enter a Microsoft device code. On the response side, security teams should revoke active refresh tokens and terminate existing sessions after a suspected compromise, review OAuth permissions, and audit mailbox forwarding rules, delegated access, and newly registered devices, since these changes could let attackers monitor communications or retain access after remediation.

Key findings

  • Forg365 is a Telegram-distributed phishing-as-a-service platform that lowers the skill required to compromise Microsoft 365 accounts.
  • The investigated campaign used a “business-document and remittance-approval” email pretext and routed victims through multiple redirects using legitimate cloud/email services.
  • Depending on the visitor, the service can show a device-code phishing flow, an adversary-in-the-middle flow, or a decoy page to evade analysis.
  • A companion browser extension (“ForgCookie”) helps attackers generate/refresh Microsoft SSO cookies, meaning access can persist even after password resets.
  • Defenders may need to revoke refresh tokens, terminate sessions, review OAuth permissions, and audit forwarding rules/delegated access and newly registered devices.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance and Accounts Payable, Executives and executive assistants, IT service desk, Security operations / incident response.
  • Affected industries: Any organization using Microsoft 365, Finance and accounts payable teams (remittance/approval themes), Knowledge workers using document-signing and file-sharing tools.
  • Attack channels: email, website.
  • Impersonated: DocuSign / Adobe Acrobat Sign / SharePoint / OneDrive (template impersonation), Microsoft 365 sign-in + SharePoint/OneDrive (look-alike workflow).

Red flags to watch for

  • Unexpected remittance/approval request that creates urgency to act
  • Multiple redirects before reaching a Microsoft sign-in step
  • Being asked to enter a “device code” to approve a document (unusual for normal document workflows)
  • Sign-in occurs after unexpected redirects or looks slightly off from normal Microsoft login
  • Login succeeds but then you are sent to an unrelated/benign page (possible decoy behavior)
  • Unusual or repeated “silent sign-ins” shortly after you interacted with the message
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Forg365?

Forg365 is a phishing-as-a-service platform distributed via Telegram that lowers the technical skill required to compromise Microsoft 365 accounts using convincing document-themed lures.

How does the device-code phishing attack work?

A victim is directed to a legitimate Microsoft authentication process and persuaded to enter a device code, which authorizes a session that is actually controlled by the attacker.

Does resetting a password stop a Forg365 attacker?

Not necessarily. A companion browser extension can generate or refresh Microsoft SSO cookies, so access can persist even after a password reset unless refresh tokens are revoked and sessions terminated.

What should security teams check after a suspected compromise?

Teams should revoke active refresh tokens, terminate existing sessions, review OAuth permissions, and audit mailbox forwarding rules, delegated access, and newly registered devices.

Read the video transcript

You get an email: “Remittance approval required, document ready for review.” Looks like DocuSign, routes to Microsoft 365. Normal, right? Behind that email might be Forg365, a phishing-as-a-service sold on Telegram. It bounces you through redirects, then lands you on a real Microsoft page asking you to enter a device code to approve the document. Here’s the trap: that code authorizes a session Forg365 controls. They can relay your Microsoft 365 login, grab your session cookies, and even use tools like the ForgCookie extension to stay in your account after a password reset. If any email about a document or remittance tells you to enter a Microsoft device code, stop. Don’t type it in, report the message to security immediately.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

July 31, 2026
Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

July 24, 2026