# Greatness PhaaS Operators

> As of 2026-08-06, Greatness PhaaS Operators is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware, phishing. Also known as ShinyHunters. ATT&CK coverage spans 50 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1098.005 (Device Registration), T1528 (Steal Application Access Token), T1557 (Adversary-in-the-Middle).

- **Tracked threats:** 3
- **Categories:** THREAT_INTEL, MALWARE, PHISHING
- **Also known as:** ShinyHunters
- **As of:** 2026-08-06

## ATT&CK techniques observed

50 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (9), Credential Access (7), Command and Control (6), Execution (6), Persistence (6), Collection (5).

- [T1098.005](https://intel.threadlinqs.com/technique/T1098.005) Device Registration — Persistence — observed in 3 of 3 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 3 of 3 tracked threats
- [T1557](https://intel.threadlinqs.com/technique/T1557) Adversary-in-the-Middle — Credential Access — observed in 3 of 3 tracked threats
- [T1566.002](https://intel.threadlinqs.com/technique/T1566.002) Spearphishing Link — Initial Access — observed in 3 of 3 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 2 of 3 tracked threats
- [T1069.003](https://intel.threadlinqs.com/technique/T1069.003) Cloud Groups — Discovery — observed in 2 of 3 tracked threats
- [T1087.004](https://intel.threadlinqs.com/technique/T1087.004) Cloud Account — Discovery — observed in 2 of 3 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 3 tracked threats
- [T1114.002](https://intel.threadlinqs.com/technique/T1114.002) Remote Email Collection — Collection — observed in 2 of 3 tracked threats
- [T1204.001](https://intel.threadlinqs.com/technique/T1204.001) Malicious Link — Execution — observed in 2 of 3 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 2 of 3 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 3 tracked threats
- [T1550.001](https://intel.threadlinqs.com/technique/T1550.001) Application Access Token — Lateral Movement — observed in 2 of 3 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 2 of 3 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 3 tracked threats

## Tracked threats

- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2](https://intel.threadlinqs.com/threat/TL-2026-2893) — HIGH
- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens](https://intel.threadlinqs.com/threat/TL-2026-1873) — HIGH
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1871) — HIGH

## Related CVEs

2 CVEs referenced by tracked Greatness PhaaS Operators activity.

- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators
