Activity timeline
Greatness PhaaS Operators appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1098.005 Device Registration — Persistenceobserved in 3 of 3 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 3 of 3 tracked threats
- T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 3 tracked threats
- T1059.007 JavaScript — Executionobserved in 2 of 3 tracked threats
- T1069.003 Cloud Groups — Discoveryobserved in 2 of 3 tracked threats
- T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1114.002 Remote Email Collection — Collectionobserved in 2 of 3 tracked threats
- T1204.001 Malicious Link — Executionobserved in 2 of 3 tracked threats
- T1530 Data from Cloud Storage — Collectionobserved in 2 of 3 tracked threats
- T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 3 tracked threats
- T1550.001 Application Access Token — Lateral Movementobserved in 2 of 3 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 2 of 3 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 3 tracked threats
Tracked threats
- QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2HIGH
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth TokensHIGH
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 AccountsHIGH