The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.
The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa.
It evolved over the years and now targets multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace.
Currently, it is sold for $289 per month to cybercriminals over a Telegram channel with thousands of subscribers.

Source: ZeroBEC
In a recent campaign observed by researchers at email security company ZeroBEC, Greatness operators abused the RingCentral communications platform to bypass email security filters on the recipient side.
RingCentral is a communications platform used by businesses for services such as cloud calling, messaging, and voicemail.
In the Greatness phishing activity, the attacker impersonated the platform by claiming their emails came from service@ringcentral[.]com, targeting actual users of the service.
These emails used fake voicemail and performance-review notifications as lures to entice recipients to open them.
Although the messages originated from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, they were still accepted by the receiving systems because RingCentral was whitelisted.
Moreover, the emails included a fraudulent banner claiming that the sender had been verified by the organization’s safe-sender list, which helped reduce suspicion at the human level.

Source: ZeroBEC
ZeroBEC explains that the tactic achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, allowing them to bypass the normal email filtering stages.
Clicking the button embedded in those emails took victims to the Greatness infrastructure, where they were routed either through a Microsoft adversary-in-the-middle (AiTM) phishing flow that captured an MFA-approved authentication token or through a device-code phishing flow.

Source: ZeroBEC
Post-compromise, the attacker replayed Microsoft 365 authentication tokens from VPS and commercial VPN infrastructure to access the compromised accounts.
They then enumerated Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications through Microsoft Graph, with access persisting for more than two weeks in some cases.
It should be noted that RingCentral recently disclosed a data breach incident which was claimed by threat actor ShinyHunters.
“This incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly,” explained the company in a security bulletin published July 28.
ZeroBEC comments that it’s likely that cybercriminals using Greatness got a list of valid targets, users of the RingCentral platform, from that incident, though a connection cannot be confidently made.
The researchers recommend auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication.
Also, hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses.
If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.




