A new phishing-as-a-service (PhaaS) platform, Forg365, is being distributed through Telegram, lowering the barrier to Microsoft 365 account compromise by automating AI-assisted phishing lures and exploiting device code and adversary-in-the-middle (AiTM) authentication flows.
What is the threat?
Forg365 provides operators with a centralized platform for creating phishing campaigns, harvesting credentials and session data, and managing post-compromise activity. The service supports device-code phishing and AiTM attacks and includes a browser extension, ForgCookie, that can hijack active Microsoft SSO sessions to maintain access to compromised accounts.
Why is it noteworthy?
Forg365 packages several advanced Microsoft 365 attack techniques into a subscription-based service, significantly lowering the technical expertise required to conduct sophisticated account compromise campaigns. By abusing legitimate Microsoft authentication workflows, attackers can capture session tokens and gain access without relying solely on stolen passwords.
Because these authentication events often appear legitimate, traditional security controls may struggle to distinguish malicious activity from normal user behavior. The platform’s ability to hijack and reuse authenticated sessions can also allow attackers to bypass MFA and maintain access for extended periods.
What is the exposure or risk?
Upon a successful compromise, threat actors can conduct business email compromise (BEC), steal sensitive data, take over user accounts, and send fraudulent communications from trusted identities. Attackers may also establish persistent access to mailboxes and Microsoft 365 resources, allowing them to continue operating even after credentials have been changed.
What are the recommendations?
Barracuda recommends the following actions to mitigate risk:
- Educate users to recognize suspicious authentication requests, verify unexpected login prompts through trusted channels, and avoid entering login codes received through email, chat, or meeting invites.
- Remind users to treat urgent or unexpected messages with caution. Even when they appear to originate from trusted contacts, vendors, or IT staff.
- Restrict or disable Microsoft device-code authentication in Entra ID where it is not required.
- Deploy phishing-resistant MFA, such as FIDO2/WebAuthn passkeys.
Use Conditional Access policies to limit access to compliant devices and trusted locations. - Terminate active sessions, revoke refresh tokens, and remove unauthorized OAuth permissions following a suspected compromise.
- Remove unauthorized mailbox rules, registered devices, authenticators, and other persistence mechanisms identified during an investigation.
References
For more in-depth information about the recommendations, please visit the following link:
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.

