Phishing Service – Steals Microsoft 365 Accounts

Overview

The Greatness phishing‑as‑a‑service (PhaaS) platform has expanded its arsenal, moving beyond credential theft into adversary‑in‑the‑middle (AiTM) attacks and device‑code phishing. In its latest campaign, Greatness operators spoofed RingCentral, a popular communications platform, to bypass email security filters and compromise Microsoft 365 accounts.

How the Attack Works

  • Spoofed emails: Messages impersonated RingCentral, using service@ringcentral[.]com as the sender.
  • Lures: Fake voicemail and performance‑review notifications enticed recipients to click.
  • Bypassing filters: Despite failing SPF, DMARC, and DKIM checks, emails were accepted because RingCentral was whitelisted.
  • Fraudulent banners: Claimed the sender was verified, reducing suspicion at the human level.

Greatness Infrastructure

Clicking the embedded button redirected victims to Greatness servers, where attackers deployed:

  • AiTM phishing flows: Captured MFA‑approved authentication tokens.
  • Device‑code phishing flows: Exploited Microsoft Entra ID authentication.
  • Tenant‑specific branding: Made phishing pages look authentic to each organization.

Post‑Compromise Activity

Once inside, attackers replayed stolen tokens from VPS and VPN infrastructure to access accounts. They enumerated:

  • Outlook mailboxes
  • Teams conversations
  • SharePoint sites
  • OneDrive files
  • Contacts and calendars
  • Registered applications via Microsoft Graph

Access persisted for over two weeks in some cases.

Context: RingCentral Breach

RingCentral recently disclosed a data breach claimed by ShinyHunters, affecting a limited portion of customers.

  • ZeroBEC researchers suggest Greatness operators may have leveraged this breach to identify valid RingCentral users, though the connection remains unconfirmed.

Defensive Guidance

  • Audit safe‑sender lists: Replace blanket domain exclusions with rules requiring valid authentication.
  • Hunt Greatness infrastructure: Monitor for suspicious MFA‑approved sign‑ins from hosting or VPN addresses.
  • Revoke tokens: Reset access and refresh tokens if compromise is suspected.
  • Review OAuth consent: Check for unauthorized applications or suspicious Graph activity.
  • Educate users: Train staff to question “verified sender” banners and unexpected notifications.

Expert in the Cloud Insight

The Greatness campaign illustrates how trusted platforms like RingCentral can be weaponized to bypass technical defenses and exploit human trust. By combining spoofed emails with AiTM and device‑code phishing, attackers gain persistent access to Microsoft 365 environments. For defenders, the lesson is clear: safe‑sender lists must be audited, MFA tokens must be monitored, and phishing‑resistant authentication should be enforced.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.