
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that can bypass normal login protections by stealing sessions or abusing Microsoft device codes. The service is sold via Telegram and uses legitimate email infrastructure (e.g., Amazon SES and SendGrid) plus anti-bot checks to blend in and avoid detection, then supports follow-on mailbox monitoring and message drafting.
Forg365 is a phishing-as-a-service kit sold via Telegram that targets Microsoft 365 accounts. It relies on business document-themed or remittance approval lures designed to get recipients, particularly in finance and accounts payable, to click malicious links. To avoid detection, the emails are sent through legitimate infrastructure such as Amazon SES, with SendGrid-hosted images or tracking resources embedded in the message body. The link chain eventually resolves to Forg365-controlled domains, but the early hops look like normal business traffic.
What makes Forg365 notable is a device-auth phishing branch. Instead of harvesting a password directly, it presents a Microsoft-styled verification code page and pushes the victim into a real Microsoft Authentication Broker sign-in flow. The victim sees genuine Microsoft authentication surfaces, but completing the flow authorizes a session for the attacker. A separate adversary-in-the-middle path uses stolen session cookies and traffic classification, including redirecting VPN users to benign decoy content to avoid tipping off defenders or automated scanners.
Several factors make this kit effective:
Employees, especially in finance, accounts payable, and executive support roles, should treat unexpected document or remittance approval requests as high-risk until verified through a separate channel. Red flags include:
Organizations can reduce exposure by blocking device code authentication unless it is genuinely required, reviewing mailbox artifacts after any device code sign-in event for unusual activity, and auditing mail-flow rules for unexpected changes. Pairing these controls with user training on device-code abuse and verification of payment or document requests through known channels can help limit the impact of kits like Forg365, which rely on blending real authentication experiences with attacker infrastructure.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Forg365 is a subscription phishing-as-a-service operation distributed via Telegram that targets Microsoft 365 accounts using document and remittance-themed lures.
Forg365 presents a Microsoft-styled verification code page that pushes victims into a legitimate Microsoft Authentication Broker sign-in flow, so the victim sees real Microsoft authentication surfaces while the code actually authorizes an attacker-controlled session.
The kit uses legitimate email delivery infrastructure such as Amazon SES and SendGrid-hosted images and tracking resources, making the traffic look normal before it ultimately routes to Forg365-controlled domains.
Recommended steps include blocking device code authentication unless required, reviewing mailbox artifacts after device code events, and auditing mail-flow rules for signs of unusual activity.
You get an email: “Remittance approval needed today.” Looks normal, even sent via Amazon SES. You click, and Forg365 quietly takes over. First a fake document page, then a Microsoft-styled device code screen that shoves you into a real Microsoft sign-in. Here’s the trick: that device code authorizes their session, not yours. They end up inside your mailbox, watching for payments and even drafting replies in your existing threads. If you ever see a Microsoft device code or login prompt from a document or payment email you didn’t start yourself, stop. Close it, and call the sender or IT on a known number to confirm.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to…

Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…