Forg365 is a phishing-as-a-service operation focused on compromising Microsoft 365 accounts. It uses both adversary-in-the-middle phishing and device-code phishing to obtain access to victim accounts, capture session material, and abuse legitimate OAuth authentication flows. The operation incorporates AI-assisted lure generation into its operator workflow, indicating a service model designed to streamline phishing campaign creation and scaling. The platform provides operators with a management dashboard for creating campaigns, managing phishing links, configuring OAuth applications and SMTP profiles, and handling stolen authentication material. Reported post-compromise functionality includes token management, mailbox keyword monitoring, and account intelligence features that help operators identify valuable messages and maintain access to compromised tenants. A notable component associated with Forg365 is ForgCookie, a browser extension for Chromium-based browsers that refreshes Microsoft single sign-on cookies through a silent OAuth process. This capability is intended to preserve persistent access to compromised Microsoft services without requiring repeated victim interaction. Forg365 also demonstrates mature defense-evasion and anti-analysis measures. Reported protections include bot detection, debugger traps, sandbox checks, encrypted redirectors, polymorphic code, and conditional redirection of suspected researchers to benign content. Operationally, the service has been observed using common phishing infrastructure and legitimate cloud-based delivery services to support email distribution, landing pages, and campaign management. Forg365 appears closely aligned with credential and session theft against enterprise cloud identities, particularly Microsoft 365 users. Similarities have been noted with other Microsoft-focused phishing kits such as Kali365 and Sneaky2FA, although no confirmed attribution link has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.