Threat reportPhishingTL-2026-1871
Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts
Greatness PhaaS Platform Spoofs RingCentral in (TL-2026-1871) is a high-severity phishing campaign, first published 2026-08-04. It is attributed to Greatness PhaaS Operators with low confidence, affects Microsoft Microsoft 365 / Entra ID, maps to 25 MITRE ATT&CK techniques (T1059.007, T1069.003, T1070.006), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 2Greatness PhaaS Operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1871
- Threat ID
- TL-2026-1871
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Greatness PhaaS Operators, ShinyHunters
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, health, technology, real-estate, financial-services
- Target regions
- North America, Europe, australia
- Detection rules
- 9
- Indicators of compromise
- 27
How Greatness PhaaS Platform Spoofs RingCentral in works
The Greatness phishing-as-a-service platform, active since at least mid-2022 and sold via Telegram for $289/month, is being used to spoof RingCentral voicemail and performance-review notifications to steal Microsoft 365 credentials and MFA-approved authentication tokens. The campaign exploits trusted safe-sender whitelists at RingCentral customer organizations to achieve SCL -1 bypass on Microsoft Exchange — delivering phishing emails that fail SPF, DKIM, and DMARC yet reach inboxes. Three attack modalities are deployed: adversary-in-the-middle (AiTM) proxy for real-time session cookie theft, OAuth 2.0 Device Authorization Grant (device code) phishing that bypasses MFA entirely, and OAuth consent abuse. Post-compromise, attackers replay tokens from VPS/VPN infrastructure within minutes, register rogue devices for Primary Refresh Token (PRT) persistence lasting over two weeks, enumerate Microsoft Graph API resources (Outlook, Teams, SharePoint, OneDrive, Contacts, Calendars, registered applications), and set malicious inbox rules for delayed egress. ZeroBEC research links the targeting to a July 2026 RingCentral data breach claimed by ShinyHunters (623 GB alleged, unconfirmed), though a direct connection cannot be confidently established.
Greatness is a commercial phishing-as-a-service (PhaaS) platform first publicly documented by Cisco Talos in May 2023, with observed activity since at least mid-2022. Originally focused exclusively on Microsoft 365 credential harvesting via HTML email attachments and a proxy-based adversary-in-the-middle mechanism, the platform has evolved into a multi-vector threat supporting three distinct attack modalities: AiTM credential/session theft, OAuth 2.0 Device Authorization Grant (device code) phishing, and OAuth consent abuse. The platform is distributed via Telegram (@GreatnessPage, 3,250+ subscribers) with operator panel access through @gr8managerbot and developer contact @greatnessmgr. Subscription pricing has risen from approximately $120/month in early 2024 to $289/month in 2025-2026, reflecting expanded capabilities including HTML and malicious SVG attachment templates. The platform targets Microsoft 365, iCloud, Yahoo, and Google Workspace, though Microsoft 365 remains the primary focus.
The RingCentral spoofing campaign represents a sophisticated operational security (OPSEC) adaptation. Attackers impersonated RingCentral by spoofing the sender address service@ringcentral[.]com and crafted lure emails mimicking voicemail notifications and performance-review alerts. Crucially, the phishing messages originated from an unknown IONOS mail server and failed SPF and DKIM authentication checks, yet were delivered to inboxes because RingCentral was present on recipient organizations' safe-sender whitelists — exploiting the trusted relationship RingCentral had established as a legitimate business communications provider. This achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, completely bypassing normal email filtering stages. A fraudulent banner embedded in the email claimed the sender was verified by the organization's safe-sender list, further reducing human suspicion.
The AiTM attack flow executes as follows: (1) the victim clicks a link in the spoofed email; (2) a five-stage redirect chain applies User-Agent fingerprinting, anti-analysis checks, and a CAPTCHA gate; (3) the victim reaches either an AiTM proxy or a device code endpoint; (4) in the AiTM path, credentials are proxied in real-time to Microsoft's legitimate authentication system, capturing the authenticated session cookie; (5) in the device code path, the victim is presented with a short authentication code and a plausible pretext to enter it on microsoft.com/devicelogin — the legitimate Microsoft device login portal — completing MFA themselves, at which point the attacker's polling loop captures the resulting access and refresh tokens. The device code variant is considered operationally cleaner for attackers as it requires no fake login page and fully satisfies MFA on the victim's side.
Post-compromise activity is methodical. Harvested tokens are replayed within minutes from dedicated proxy infrastructure on VPS and commercial VPN networks. One observed AiTM proxy IP (38.248.95.214) continued authenticating against a victim's account more than two weeks after the initial phishing campaign. Attackers perform device registration in Entra ID within minutes of gaining initial access to generate a Primary Refresh Token (PRT) — a credential that survives password resets and Microsoft's most common first-response action. Attackers then enumerate Microsoft Graph API resources systematically: Outlook mailboxes (email content), Teams conversations (chat history and channel data), SharePoint sites (document libraries), OneDrive files (personal cloud storage), contacts, calendars, and registered OAuth applications. A deliberate delay of several hours precedes the creation of malicious inbox rules and data exfiltration, reducing the likelihood of immediate detection. The compromised account's trust is then leveraged for cascaded phishing campaigns against partners, vendors, and third parties.
According to Sekoia.io's global analysis of AiTM phishing threats (January-April 2025), Greatness was ranked 8th among 11 tracked kits with a global score of 2.0/5, behind Tycoon 2FA (4.8), Storm-1167 (4.2), NakedPages (4.0), Sneaky 2FA (3.6), EvilProxy (3.2), Evilginx/ywnjb (3.2), and Saiga 2FA (2.0). Despite its lower ranking, the platform's sustained operation since mid-2022, integration of three distinct phishing modalities, and adaptation to the RingCentral breach nexus demonstrate ongoing threat relevance. The Cisco Talos IOC repository lists over 200 SHA256 hashes of phishing attachment payloads and hundreds of compromised domains hosting Greatness admin panels accessed via the path pattern */admin/js/mj.php.
The RingCentral nexus adds operational context. On July 27, 2026, the ShinyHunters threat group listed RingCentral on its dark web leak portal demanding contact by July 30. Following the deadline's passage, on August 3, 2026, ShinyHunters updated the listing claiming exfiltration of 623 GB of uncompressed data (280 GB compressed), including 21,969 end-user account records, 120 internal employee credentials, and 173 third-party employee credentials. The listing included an SHA-256 checksum but no published sample files. RingCentral has not issued an official breach notification, and the claims remain unconfirmed as of August 4, 2026. ZeroBEC researchers noted that attackers using Greatness may have obtained target lists from this breach data, but stated a connection cannot be confidently made. RingCentral customers are advised to treat the breach disclosure as a trigger to audit and tighten email exclusion rules for RingCentral's domains.
MITRE ATT&CK techniques used in TL-2026-1871
Execution
T1059.007 JavaScript; T1204.001 Malicious Link; T1204.002 Malicious File
Discovery
T1069.003 Cloud Groups; T1087.004 Cloud Account
Defense Evasion
T1070.006 Timestomp; T1564.008 Email Hiding Rules
Persistence
T1078.004 Cloud Accounts; T1098.002 Additional Email Delegate Permissions; T1098.005 Device Registration
Command and Control
T1090.002 External Proxy; T1102.003 One-Way Communication
Collection
T1114.002 Remote Email Collection; T1114.003 Email Forwarding Rule; T1213.002 Sharepoint; T1213.003 Code Repositories; T1530 Data from Cloud Storage
Initial Access
T1199 Trusted Relationship; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Credential Access
T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle; T1606.001 Web Cookies
Lateral Movement
T1550.001 Application Access Token
defense-impairment
Affected products and versions in Greatness PhaaS Platform Spoofs RingCentral in
- Microsoft — Microsoft 365 / Entra ID
Vulnerable versions: All versions with OAuth device code flow enabled; All versions with safe-sender whitelists - Microsoft — Microsoft Exchange Online
Vulnerable versions: All versions susceptible to SCL -1 bypass via safe-sender abuse - RingCentral — RingCentral Communications Platform
Vulnerable versions: All versions (brand targeted for spoofing)
Remediation for Greatness PhaaS Platform Spoofs RingCentral in
Immediate actions
- Audit and remove blanket safe-sender list entries for all vendor domains; replace with rules requiring valid SPF/DKIM/DMARC authentication
- Implement Conditional Access policies to block the OAuth 2.0 Device Authorization Grant (device code) authentication flow globally
- Deploy phishing-resistant MFA methods (FIDO2/WebAuthn) for all privileged accounts
- If compromise is suspected, revoke all access and refresh tokens for affected accounts
- Review OAuth consent grants and remove any suspicious or unauthorized applications
- Audit Microsoft Graph API activity logs for anomalous enumeration or data access patterns
Workarounds
- Block device code authentication flow globally in Conditional Access (Microsoft began auto-provisioning this for eligible tenants in February 2025)
- Use Snort SID 61708 (Cisco coverage) for network-level detection of Greatness phishing infrastructure
- Block known Greatness phishing domains and IPs at perimeter via DNS filtering and web proxy
Longer-term hardening
- Treat vendor breach disclosures as a trigger to audit and tighten email exclusion rules for the affected vendor's domains
- Deploy behavioral detection for token replay from hosting/VPN IP addresses in Microsoft 365 sign-in logs
- Implement continuous auditing of device code flow usage with explicit exclusion lists for only necessary users/resources
- Deploy Entra ID Identity Protection with risk-based Conditional Access policies
- Conduct regular reviews of safe-sender whitelists and email authentication configurations
- Implement KQL hunting queries correlating sign-in logs with Microsoft Graph Activity Logs to detect token replay outside compliant networks
Timeline of Greatness PhaaS Platform Spoofs RingCentral in
- Greatness PhaaS platform first observed active in the wild, targeting Microsoft 365 credentials via HTML email attachments with proxy-based AiTM credential harvesting
- First significant activity spike detected in VirusTotal attachment submissions for Greatness phishing kit payloads
- Second activity spike in Greatness phishing kit samples submitted to VirusTotal; growing adoption among cybercriminal affiliates
- Cisco Talos publishes first comprehensive analysis of the Greatness PhaaS platform, detailing its proxy-based AiTM mechanism, Telegram bot integration, and MFA bypass capabilities. Over 200 SHA256 hashes and hundreds of compromised domains published in IOC repository
- Greatness expands targeting to include iCloud, Yahoo, and Google Workspace in addition to Microsoft 365; subscription pricing at approximately $120/month
- Trellix publishes in-depth technical analysis 'Tale of Greatness: Journey Through Dark Roads' detailing phishing kit architecture, JavaScript obfuscation techniques, and attack chain mechanics
- Greatness adds OAuth 2.0 Device Authorization Grant (device code) phishing capability, enabling MFA bypass without a fake login page — victims authenticate on the legitimate Microsoft device login portal while the attacker captures tokens via background polling
- Microsoft begins auto-provisioning Conditional Access policies blocking Device Code Flow for eligible tenants as a defensive measure against the surge in device code phishing attacks
- Sekoia.io publishes global AiTM phishing threat analysis ranking Greatness 8th among 11 tracked kits (score 2.0/5); notes expansion to HTML and malicious SVG attachment templates for link distribution. Tycoon 2FA ranked first (4.8/5)
- Greatness subscription pricing reaches $289/month, a 2.4x increase from early 2024, reflecting expanded capabilities including three attack modalities, 11+ downloadable lure templates, and Telegram bot integration
- Microsoft publishes analysis of AI-enabled device code phishing campaigns documenting the technique's effectiveness: dynamic device code generation bypasses 15-minute OAuth expiration, PRT registration enables persistence surviving password resets
- ShinyHunters threat group lists RingCentral on dark web leak portal as part of multi-victim campaign alongside Ernst & Young and Brink's Home; sets July 30 negotiation deadline
- RingCentral extortion deadline passes without public confirmation of resolution; no official statement issued by RingCentral
- ShinyHunters updates RingCentral leak listing claiming 623 GB uncompressed data exfiltrated (280 GB compressed), including 21,969 end-user account records, 120 internal employee credentials, and 173 third-party employee credentials; SHA-256 checksum published but no sample files released. Claims remain unconfirmed
- BleepingComputer and The Hacker News report Greatness PhaaS campaign spoofing RingCentral voicemail and performance-review notifications. ZeroBEC research details AiTM, device code phishing, PRT registration, and post-compromise Graph API enumeration. Connection to ShinyHunters RingCentral breach noted as possible but unconfirmed source of target lists
Sources cited for Greatness PhaaS Platform Spoofs RingCentral in
- Phishing service spoofs RingCentral to steal Microsoft 365 accounts
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- New phishing-as-a-service tool 'Greatness' already seen in the wild
- New 'Greatness' Phishing-as-a-Service Targets Microsoft 365 Accounts
- ZeroBEC Research: Greatness PhaaS — AiTM and Device Code Phishing
- Tale of Greatness: Journey Through Dark Roads
- Global analysis of Adversary-in-the-Middle phishing threats
- Inside an AI-enabled device code phishing campaign
- Cisco Talos Greatness IOC Repository
- Device Code Flow: The Gift That Keeps on Giving — to Attackers
- ShinyHunters Allegedly Claims RingCentral Data Breach
- ShinyHunters adds EY, RingCentral, and Brinks Home to data leak site
- OAuth Device Code Phishing: 37x Surge in Enterprise ATO
- Greatness PhaaS Platform on ANY.RUN Malware Trends
- Realt Hacker News: Greatness PhaaS Adds Device Code Phishing
Detection coverage for TL-2026-1871
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1871 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.