
Forg365 Phishing Kit Steals Microsoft 365 Sessions
Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…
Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue login tokens directly to the attacker. Because the victim completes a legitimate MFA-approved sign-in on a legitimate Microsoft URL, the activity can look normal and may bypass some Conditional Access patterns. The result is persistent access via refresh tokens, often leading to mailbox access, inbox rule tampering, and business email compromise (BEC).
This attack abuses a legitimate Microsoft 365 sign-in mechanism called the device code flow, which is normally used to authenticate devices that lack a browser, such as smart TVs or command-line tools. In this scenario, an attacker initiates the device code flow themselves and generates a code. They then craft an email, often framed as a shared document notification, that pressures the recipient to visit a lookalike site and eventually enter that code at the real microsoft.com/devicelogin page. Because the user is entering the code on Microsoft's own domain and approving a legitimate MFA prompt, Entra ID issues authentication tokens, including refresh tokens, directly to the attacker's polling client rather than to the victim's own session.
The core reason this technique works is that every visible signal looks normal to the victim. The MFA prompt is real, the login page is Microsoft's actual domain, and the sign-in itself completes successfully. There is no fake login page to spot and no obviously spoofed domain to flag. The victim believes they are simply confirming access to a shared document, when in reality they are handing over a token that grants the attacker ongoing access. Refresh tokens obtained this way can persist for an extended period, allowing continued access without triggering another MFA challenge.
Organizations should train employees to treat device code requests as inherently suspicious unless they personally started the device sign-in process. Incident responders need to understand that a password reset alone does not revoke refresh tokens, so token revocation must be treated as its own deliberate response step. Security operations teams should build monitoring around the Device Code authentication protocol in Entra sign-in logs and correlate those events with subsequent mailbox rule changes, since this combination is described as one of the highest-fidelity indicators of follow-on business email compromise activity.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is an attack where a victim is tricked into entering an attacker-supplied code at the real microsoft.com/devicelogin page, causing Microsoft 365 to issue login tokens to the attacker's session instead of the user's own device.
The victim completes a genuine sign-in on a legitimate Microsoft URL and approves a real MFA prompt, so from the user's perspective nothing looks wrong.
No, a password reset alone does not revoke an active refresh token; explicit token revocation is a separate step defenders must take.
Defenders can look for sign-ins where the authentication protocol is Device Code in Entra sign-in logs, and correlate these with subsequent mailbox rule changes or location mismatches.
You get an email: "Action required: A document has been shared with you." Looks internal, looks urgent. You click, land on a lookalike document site, and it tells you: go to microsoft.com slash devicelogin, enter THIS short code, then approve the MFA. That’s the trap. Because you’re on a real Microsoft page and the MFA prompt is real, it feels safe. But when you type in their code, Entra hands long‑lived refresh tokens to THEIR session, letting them read your mailbox and change inbox rules for weeks. Here’s the rule: if YOU didn’t just start a sign-in on a TV, app, or device yourself, treat any email or site telling you to enter a device code at microsoft.com slash devicelogin as phishing and report it immediately.

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…

Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…