Evolution of the Greatness Phishing Platform

Security analysts at ZeroBEC have identified a significant escalation in the tactics employed by the phishing-as-a-service (PhaaS) platform identified as "Greatness." Originally functioning as a basic credential harvesting tool, the service has expanded its capabilities to target not only Microsoft 365 but also Google Workspace, Yahoo, and iCloud accounts. Most concerningly, the platform has integrated features designed to circumvent multi-factor authentication (MFA) protocols.


The RingCentral Spoofing Operation

The current wave of attacks specifically targets RingCentral users. Researchers suggest this may be linked to a prior security incident involving the notorious hacker group ShinyHunters, which likely provided attackers with a database of customer contact information. Even though these malicious emails fail standard authentication checks like SPF and DMARC, they are crafted to appear as legitimate correspondence from RingCentral.


The lures typically include notifications regarding:

  • Fake voicemail alerts
  • Performance review notifications

Bypassing MFA Security

When recipients interact with the links in these emails, they are directed to a spoofed Microsoft 365 login portal. By utilizing this infrastructure, the operators of Greatness can capture session authentication tokens in real-time. This "Adversary-in-the-Middle" technique allows attackers to bypass MFA entirely, granting them immediate access to the victim’s account without needing secondary codes.


«Once the attackers gain entry, they can extensively monitor the victim's digital environment, including Outlook mailboxes, Microsoft Teams chats, OneDrive storage, and contact lists,» note the researchers.

Global Reach and Commercial Availability

While the exact number of compromised users remains unclear, the Greatness platform has maintained active operations for roughly four years. The threat actors focus their efforts primarily on victims located in:

  • United States
  • United Kingdom
  • Australia
  • Canada
  • South Africa

According to reports, the tool is being actively marketed on Telegram channels to a large subscriber base, with operators charging a monthly subscription fee of $289 for access to these illicit capabilities.