A new phishing-as-a-service (PhaaS) platform called Forg365 has emerged, as PhaaS kits like EvilTokens, Kali365 and others continue to gain traction with the aim of targeting Microsoft 365 accounts.

Like EvilTokens and Kali365, Forg365 is distributed through Telegram and offered as a commoditized service, complete with a five-day free trial, monthly access for $400, and annual access for $3,800. 

“Forg365 matters because it demonstrates how quickly Microsoft 365 phishing-as-a-service is becoming productized,” according to researchers with email security company ZeroBEC this week. “The platform is not merely a landing page. It packages access, lure creation, delivery, evasion, token/session handling, and post-compromise operations into a subscription-based operator environment.”

Source: ZeroBEC

Researchers first came across the panel via an email lure sent from the platform, which presented a business-document request including SendGrid-hosted images and that was sent through Amazon SES delivery.

“This mix of legitimate delivery services, hosted visual assets, and downstream phishing infrastructure is consistent with a mature PhaaS delivery model designed to blend into normal SaaS email traffic,” said researchers.

Like other PhaaS platforms, Forg365 supports device code phishing, a social engineering tactic where attackers trick victims into completing a legitimate OAuth device authorization flow, which results in them accessing the users’ tokens and gaining authenticated access. It also enables adversary-in-the-middle attacks (AiTM), where attackers proxy victim authentication sessions in real time to intercept credentials, session cookies, or tokens, and hijack authenticated sessions.

“This is the broader trend: AI makes custom PhaaS development easier, and it also makes the operator workflow more accessible."

“Entra telemetry linked the device-code branch to a Comcast/Xfinity fixed-line address and to a campaign-linked Forg365 backend hosted in Kyiv, Ukraine,” according to researchers. “The Comcast/Xfinity address appeared during Microsoft Authentication Broker/device-code activity, while the Ukraine node later performed Microsoft Graph/device-registration activity and exposed a Forg365 panel.”

Researchers also found a browser extension called ForgCookie, which is designed for Microsoft SSO cookie refreshes, browser-based access and other post-compromises workflows for attackers. The kit's operators have also embedded AI features directly into the panel to help create emails and lures, as well as for post-compromise functions - like "AI mailbox context," where operators can feed email context into AI-generated responses when parsing emails.

“This is the broader trend: AI makes custom PhaaS development easier, and it also makes the operator workflow more accessible,” according to researchers. “Operators do not need to rely only on external prompt tools or handcrafted templates. They can create and refine campaign material in the same environment that manages links, SMTP rotation, OAuth app workflows, token vaulting, and mailbox access.”

Finally, researchers said that Forg365 appears to be a “Kali365-class Microsoft 365 token-focused PhaaS platform with Sneaky 2FA-style AiTM overlap” – although they did not determine any common ownership with Kali365 or Sneaky 2FA. More PhaaS platforms have been emerging with similarities across their features - including ARToken, a recently discovered panel that goes back to the EvilTokens framework. 

“Forg365 should be classified as Kali365-class because it shares the category-defining characteristics: Telegram distribution, subscription-based access, Microsoft 365 OAuth and device-auth abuse, AI-generated lure support, automated templates, dashboards, token capture, and persistent access workflows,” said researchers.