The Rise of Phishing as a Service: What Kali365 and Forg365 Mean for Your Business 

By Justin Pence, Security Operations Readiness Analyst

Phishing used to require skill. An attacker needed to register a convincing domain, build a fake login page, and hope nobody looked too closely at the URL bar. That era is ending fast. 

Two platforms that emerged this year, known as Kali365 and Forg365, show just how far phishing has evolved. Both are Phishing as a Service kits, sold as monthly subscriptions on Telegram for a few hundred dollars. No hacking experience required. No custom infrastructure to build. Just sign up, pick a template, and launch a campaign. 

For security professionals, this is more than another headline. It represents a fundamental shift in who can carry out a sophisticated attack, and how hard those attacks are to catch. 

How These Attacks Actually Work 

What makes Kali365 and Forg365 especially dangerous is that they do not rely on stealing a password at all. Instead, they exploit a legitimate Microsoft feature called device code authentication, the same technology that lets a smart TV or streaming device log in using a short code entered on your phone. 

Here is the typical sequence. A target receives an email that looks like a routine notification from a trusted service, something like a shared document from SharePoint or a signature request from DocuSign. The email includes a short code and a link to a Microsoft verification page. The target clicks through, lands on the real Microsoft login page, and enters the code exactly as instructed. 

At that moment, without ever typing their password into a phishing page, the target may have unknowingly authorized an attacker-controlled device. If the victim successfully completes the authentication process (including MFA, if required) Microsoft issues valid OAuth tokens to the device that initiated the request. The attacker can then use those tokens to access Microsoft 365 resources such as Outlook, Teams, and OneDrive, potentially maintaining access through refresh tokens until that access is revoked or otherwise invalidated. 

Forg365 pushes this further. It combines device-code phishing with adversary-in-the-middle (AiTM) techniques that can intercept authentication sessions and session cookies. It also includes AI-assisted tooling for generating phishing lures and a browser extension designed to help maintain access to compromised Microsoft 365 accounts without requiring the attacker to repeatedly authenticate. 

Why This Should Change How You Think About Defense 

Traditional phishing training tells employees to look for warning signs. Misspelled domains. Suspicious senders. Pages that do not quite look right. Kali365 and Forg365 break that model entirely, because the page the victim sees really is Microsoft’s own login portal. There is no fake site to spot. 

This is the direction phishing is heading. Attacks are becoming productized, automated, and accessible to people with no technical background at all. The tools are getting easier to use, which means the volume and sophistication of attacks are only going to increase. 

What Organizations Can Do Right Now 

A few practical steps can meaningfully reduce your exposure to this style of attack: 

  • Restrict device code authentication wherever possible. Most organizations do not need it enabled for the majority of users, and a conditional access policy can block it while allowing exceptions for legitimate business cases. 
  • Move toward phishing resistant multi factor authentication, such as hardware security keys, which are far harder to bypass than a standard MFA prompt. 
  • Monitor for unusual sign in activity, new device registrations, and mailbox rule changes, since these are common signs of a compromised account operating quietly in the background. 
  • Update security awareness training to reflect this new reality. Employees need to understand that a legitimate looking Microsoft page is no longer proof that a request is safe. 

The Bottom Line 

Phishing as a Service platforms like Kali365 and Forg365 have lowered the skill needed to launch a serious attack, while raising the difficulty of detecting one. The organizations that adapt their defenses now, rather than waiting for an incident to force the issue, will be far better positioned to withstand what comes next. 

Ready to strengthen your defenses against the next generation of phishing attacks? Contact TekStream to learn how we can help your organization identify risk, improve visibility and protect your Microsoft 365 environment.

About the Author

Justin is a cybersecurity professional with six years of experience across the MDR and MSSP space, with a particular interest in threat hunting and staying ahead of emerging threat actors and tactics. Based in North Carolina, Justin currently works in the University Workforce Academy space, helping prepare the next generation of cybersecurity professionals for the challenges of an evolving threat landscape.