Forg365 Phishing Kit Steals Microsoft 365 Sessions

The Hacker News · High sophistication
Last updated July 30, 2026

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that can bypass normal login protections by stealing sessions or abusing Microsoft device codes. The service is sold via Telegram and uses legitimate email infrastructure (e.g., Amazon SES and SendGrid) plus anti-bot checks to blend in and avoid detection, then supports follow-on mailbox monitoring and message drafting.

How the Forg365 attack chain works

Forg365 is a phishing-as-a-service kit sold via Telegram that targets Microsoft 365 accounts. It relies on business document-themed or remittance approval lures designed to get recipients, particularly in finance and accounts payable, to click malicious links. To avoid detection, the emails are sent through legitimate infrastructure such as Amazon SES, with SendGrid-hosted images or tracking resources embedded in the message body. The link chain eventually resolves to Forg365-controlled domains, but the early hops look like normal business traffic.

The device-code and session-theft angle

What makes Forg365 notable is a device-auth phishing branch. Instead of harvesting a password directly, it presents a Microsoft-styled verification code page and pushes the victim into a real Microsoft Authentication Broker sign-in flow. The victim sees genuine Microsoft authentication surfaces, but completing the flow authorizes a session for the attacker. A separate adversary-in-the-middle path uses stolen session cookies and traffic classification, including redirecting VPN users to benign decoy content to avoid tipping off defenders or automated scanners.

Why this approach succeeds

Several factors make this kit effective:

  • Legitimate email delivery services make sender reputation checks less useful as a signal.
  • Document and payment-approval pretexts create urgency without requiring obviously suspicious content.
  • Device-code phishing exploits a legitimate Microsoft sign-in flow, so the authentication experience itself looks authentic.
  • Post-compromise tooling can monitor mailbox keywords and draft AI-assisted replies inside existing email threads, extending the attack beyond initial access.

What to watch for

Employees, especially in finance, accounts payable, and executive support roles, should treat unexpected document or remittance approval requests as high-risk until verified through a separate channel. Red flags include:

  • Being prompted to enter or approve a device code you did not initiate yourself.
  • Authentication prompts appearing after clicking a link tied to a document or payment request.
  • Externally hosted tracking images or links that pass through several redirects before landing on an unfamiliar domain.

Building resistance

Organizations can reduce exposure by blocking device code authentication unless it is genuinely required, reviewing mailbox artifacts after any device code sign-in event for unusual activity, and auditing mail-flow rules for unexpected changes. Pairing these controls with user training on device-code abuse and verification of payment or document requests through known channels can help limit the impact of kits like Forg365, which rely on blending real authentication experiences with attacker infrastructure.

Key findings

  • Forg365 is a subscription phishing-as-a-service operation distributed via Telegram that targets Microsoft 365 accounts.
  • Observed lures include business document-themed and remittance approval messages designed to get users to click malicious links.
  • Attack delivery can use legitimate email services (Amazon SES) and SendGrid-hosted images/tracking to look like normal traffic.
  • A device-code phishing path shows Microsoft-styled pages and pushes victims into a legitimate Microsoft sign-in flow that authorizes an attacker-controlled session.
  • An adversary-in-the-middle (AitM) path uses session cookies and traffic classification, including redirecting VPN users to benign decoy content.
  • Post-compromise tooling includes monitoring mailbox keywords and AI-assisted drafting of replies within existing email threads.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Accounts Payable, Executives, Executive Assistants, IT / Identity & Access Management.
  • Affected industries: Multiple / cross-industry (Microsoft 365 users).
  • Attack channels: email, website, smishing.
  • Impersonated: Business partner/vendor (generic) using legitimate email delivery services, Microsoft sign-in / Microsoft Authentication Broker, U.S. Postal Service (USPS) or UPS.

Red flags to watch for

  • Email infrastructure looks legitimate (SES/SendGrid) but the link chain ends on attacker-controlled domains
  • Document/payment urgency without prior context
  • Embedded tracking resources/images hosted externally
  • You are prompted to enter/approve a device code you did not initiate
  • Login experience looks real, but was initiated from an unexpected link
  • Unexpected authentication prompts tied to a document/payment lure
  • Unexpected delivery problem message with a link
  • Request for card/payment details to fix delivery
  • Pressure to act immediately to avoid return/cancellation
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Forg365?

Forg365 is a subscription phishing-as-a-service operation distributed via Telegram that targets Microsoft 365 accounts using document and remittance-themed lures.

How does the device-code phishing technique work?

Forg365 presents a Microsoft-styled verification code page that pushes victims into a legitimate Microsoft Authentication Broker sign-in flow, so the victim sees real Microsoft authentication surfaces while the code actually authorizes an attacker-controlled session.

Why do Forg365 emails avoid spam filters?

The kit uses legitimate email delivery infrastructure such as Amazon SES and SendGrid-hosted images and tracking resources, making the traffic look normal before it ultimately routes to Forg365-controlled domains.

What can organizations do to reduce risk from device-code phishing?

Recommended steps include blocking device code authentication unless required, reviewing mailbox artifacts after device code events, and auditing mail-flow rules for signs of unusual activity.

Read the video transcript

You get an email: “Remittance approval needed today.” Looks normal, even sent via Amazon SES. You click, and Forg365 quietly takes over. First a fake document page, then a Microsoft-styled device code screen that shoves you into a real Microsoft sign-in. Here’s the trick: that device code authorizes their session, not yours. They end up inside your mailbox, watching for payments and even drafting replies in your existing threads. If you ever see a Microsoft device code or login prompt from a document or payment email you didn’t start yourself, stop. Close it, and call the sender or IT on a known number to confirm.

Similar attacks