Evolution of the Greatness Phishing Platform
Security analysts at ZeroBEC have identified a significant escalation in the tactics employed by the phishing-as-a-service (PhaaS) platform identified as "Greatness." Originally functioning as a basic credential harvesting tool, the service has expanded its capabilities to target not only Microsoft 365 but also Google Workspace, Yahoo, and iCloud accounts. Most concerningly, the platform has integrated features designed to circumvent multi-factor authentication (MFA) protocols.
The RingCentral Spoofing Operation
The current wave of attacks specifically targets RingCentral users. Researchers suggest this may be linked to a prior security incident involving the notorious hacker group ShinyHunters, which likely provided attackers with a database of customer contact information. Even though these malicious emails fail standard authentication checks like SPF and DMARC, they are crafted to appear as legitimate correspondence from RingCentral.
The lures typically include notifications regarding:
- Fake voicemail alerts
- Performance review notifications
Bypassing MFA Security
When recipients interact with the links in these emails, they are directed to a spoofed Microsoft 365 login portal. By utilizing this infrastructure, the operators of Greatness can capture session authentication tokens in real-time. This "Adversary-in-the-Middle" technique allows attackers to bypass MFA entirely, granting them immediate access to the victim’s account without needing secondary codes.
«Once the attackers gain entry, they can extensively monitor the victim's digital environment, including Outlook mailboxes, Microsoft Teams chats, OneDrive storage, and contact lists,» note the researchers.
Global Reach and Commercial Availability
While the exact number of compromised users remains unclear, the Greatness platform has maintained active operations for roughly four years. The threat actors focus their efforts primarily on victims located in:
- United States
- United Kingdom
- Australia
- Canada
- South Africa
According to reports, the tool is being actively marketed on Telegram channels to a large subscriber base, with operators charging a monthly subscription fee of $289 for access to these illicit capabilities.
