425/69 Thursday, August 6, 2026

Reports indicate that Greatness, a Phishing-as-a-Service (PhaaS) platform, has evolved from credential theft to Adversary-in-the-Middle (AiTM) attacks and device-code phishing to target Microsoft 365 accounts. The platform has been active since 2022 and previously targeted Microsoft 365 users in the United States, Canada, the United Kingdom, Australia, and South Africa. Greatness has now expanded its targets to multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace, and is being offered to cybercriminal groups through Telegram for USD 289 per month.
In a recent campaign identified by researchers at email security firm ZeroBEC, Greatness operators impersonated RingCentral, a communications platform used by organizations for cloud calling, messaging, and voicemail, to bypass recipients’ email security filters. The phishing emails claimed to be sent from service@ringcentral[.]com and targeted real RingCentral users. The messages used lures involving fake voicemail notifications and performance review alerts to encourage victims to open them. Although the emails were sent from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, the receiving systems still accepted them because RingCentral was included in the organization’s safe-sender list or whitelist. The emails also included a fake banner claiming that the sender had been verified by the organization’s safe-sender list to reduce user suspicion.
When victims clicked the button in the email, they were directed to Greatness infrastructure and redirected into a Microsoft AiTM phishing flow to steal MFA-approved authentication tokens, or into a device-code phishing flow. After gaining access to the account, the attackers replayed Microsoft 365 authentication tokens through VPS and commercial VPN infrastructure to access the compromised accounts. They then inspected Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications through Microsoft Graph. In some cases, access persisted for more than two weeks. ZeroBEC stated that it is possible Greatness users obtained target lists of RingCentral users from a recent RingCentral data breach disclosed by the company and claimed by ShinyHunters, but this connection has not been confirmed. Researchers recommend that organizations review safe-sender lists, avoid unconditional domain-wide allowlisting, detect Microsoft 365 sign-ins that pass MFA from unusual hosting or VPN addresses, and, if account compromise is suspected, revoke all access and refresh tokens while thoroughly reviewing OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.
