Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-08

Greatness PhaaS Operators

Also known as:ShinyHunters

As of 2026-08-06, Greatness PhaaS Operators is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware, phishing. Also known as ShinyHunters. ATT&CK coverage spans 50 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1098.005 (Device Registration), T1528 (Steal Application Access Token), T1557 (Adversary-in-the-Middle).

Tracked threats
33 high
First seen
2026-08-04
Last seen
2026-08-06
ATT&CK techniques
50across 3 of 3 threats
Related CVEs
2Referenced by its activity
3 tracked threat(s) · Categories: THREAT_INTEL, MALWARE, PHISHING

Activity timeline

Greatness PhaaS Operators appears in 3 tracked threats between and .

ATT&CK techniques observed

50 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (9), Credential Access (7), Command and Control (6), Execution (6), Persistence (6), Collection (5)
  • T1098.005 Device Registration — Persistenceobserved in 3 of 3 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 3 of 3 tracked threats
  • T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
  • T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 3 tracked threats
  • T1059.007 JavaScript — Executionobserved in 2 of 3 tracked threats
  • T1069.003 Cloud Groups — Discoveryobserved in 2 of 3 tracked threats
  • T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1114.002 Remote Email Collection — Collectionobserved in 2 of 3 tracked threats
  • T1204.001 Malicious Link — Executionobserved in 2 of 3 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 2 of 3 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 3 tracked threats
  • T1550.001 Application Access Token — Lateral Movementobserved in 2 of 3 tracked threats
  • T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 2 of 3 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 3 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked Greatness PhaaS Operators activity