2026-07-10NOTABLEZeroBEC details Forg365, a Telegram-sold M365 PhaaS that survives MFA and keeps operator access alive via a ForgCookie browser extension
Forg365
tool · tool:forg365-phaas
Telegram-distributed, subscription-priced ($400/month) Microsoft 365 phishing-as-a-service platform combining OAuth device-code phishing and adversary-in-the-middle session-cookie theft with an in-panel AI lure-drafting assistant and a companion browser extension (ForgCookie) that silently refreshes stolen Microsoft SSO cookies for post-compromise persistence; assessed by ZeroBEC as a Kali365-class platform with Sneaky2FA-style AiTM overlap, no asserted common ownership (ZeroBEC, 2026-07-09).
Aliases: ForgCookie
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
ZeroBEC details Forg365, a Telegram-sold M365 PhaaS that survives MFA and keeps operator access alive via a…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, healthcare
Sources cited
3
3 hosts
Action items (3)
Do-now tasks recorded on the entries about Forg365, newest first. Check the date before acting on an older one.
- Block the OAuth device-authorization flow via Entra Conditional Access (Authentication Flows → Device Code Flow → Block) except where a documented CLI/headless use case requires it, this closes the device-code path Forg365 sells.2026-07-10ZeroBEC details Forg365, a Telegram-sold M365 PhaaS…
- On any account with suspected compromise, run revokeSignInSessions in Entra ID; a password reset alone does not invalidate a device-code-derived refresh token or an AiTM-stolen session cookie.2026-07-10ZeroBEC details Forg365, a Telegram-sold M365 PhaaS…
- Hunt managed endpoints for browser extensions exhibiting SSO-cookie-refresh behavior (ForgCookie class), and alert on new OAuth app consent grants or new mailbox forwarding/inbox rules created immediately after a sign-in.2026-07-10ZeroBEC details Forg365, a Telegram-sold M365 PhaaS…
Defender insights
What each entry about Forg365 tells a defender to do, newest first.
Triage
Story timeline
ATT&CK techniques (4 across 3 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing: Spearphishing Link
- PersistenceSoftware Extensions
- Credential AccessSteal Application Access Token · Steal Web Session Cookie
Initial Access TA0001
T1566.002Phishing: Spearphishing Link×1
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie · ATT&CK page ↗
Persistence TA0003
T1176Software Extensions×1
Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access levels of the host application.
Evidence: 2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie · ATT&CK page ↗
T1539Steal Web Session Cookie×1
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Evidence: 2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie · ATT&CK page ↗
Entries about Forg365 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- labs.cloudsecurityalliance.org1 (33%)
- zerobec.com1 (33%)
All cited sources (3)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
- labs.cloudsecurityalliance.orgCloud Security Alliance (CSA Labs)https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/
- zerobec.comZeroBEChttps://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas