# Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts

> The Greatness phishing-as-a-service platform, active since at least mid-2022 and sold via Telegram for $289/month, is being used to spoof RingCentral voicemail and performance-review notifications to steal Microsoft 365 credentials and MFA-approved authentication tokens. The campaign exploits trusted safe-sender whitelists at RingCentral customer organizations to achieve SCL -1 bypass on Microsoft Exchange — delivering phishing emails that fail SPF, DKIM, and DMARC yet reach inboxes. Three attack modalities are deployed: adversary-in-the-middle (AiTM) proxy for real-time session cookie theft, OAuth 2.0 Device Authorization Grant (device code) phishing that bypasses MFA entirely, and OAuth consent abuse. Post-compromise, attackers replay tokens from VPS/VPN infrastructure within minutes, register rogue devices for Primary Refresh Token (PRT) persistence lasting over two weeks, enumerate Microsoft Graph API resources (Outlook, Teams, SharePoint, OneDrive, Contacts, Calendars, registered applications), and set malicious inbox rules for delayed egress. ZeroBEC research links the targeting to a July 2026 RingCentral data breach claimed by ShinyHunters (623 GB alleged, unconfirmed), though a direct connection cannot be confidently established.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1871
- **ID:** TL-2026-1871
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Greatness PhaaS Operators
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Greatness is a commercial phishing-as-a-service (PhaaS) platform first publicly documented by Cisco Talos in May 2023, with observed activity since at least mid-2022. Originally focused exclusively on Microsoft 365 credential harvesting via HTML email attachments and a proxy-based adversary-in-the-middle mechanism, the platform has evolved into a multi-vector threat supporting three distinct attack modalities: AiTM credential/session theft, OAuth 2.0 Device Authorization Grant (device code) phishing, and OAuth consent abuse. The platform is distributed via Telegram (@GreatnessPage, 3,250+ subscribers) with operator panel access through @gr8managerbot and developer contact @greatnessmgr. Subscription pricing has risen from approximately $120/month in early 2024 to $289/month in 2025-2026, reflecting expanded capabilities including HTML and malicious SVG attachment templates. The platform targets Microsoft 365, iCloud, Yahoo, and Google Workspace, though Microsoft 365 remains the primary focus.

The RingCentral spoofing campaign represents a sophisticated operational security (OPSEC) adaptation. Attackers impersonated RingCentral by spoofing the sender address service@ringcentral[.]com and crafted lure emails mimicking voicemail notifications and performance-review alerts. Crucially, the phishing messages originated from an unknown IONOS mail server and failed SPF and DKIM authentication checks, yet were delivered to inboxes because RingCentral was present on recipient organizations' safe-sender whitelists — exploiting the trusted relationship RingCentral had established as a legitimate business communications provider. This achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, completely bypassing normal email filtering stages. A fraudulent banner embedded in the email claimed the sender was verified by the organization's safe-sender list, further reducing human suspicion.

The AiTM attack flow executes as follows: (1) the victim clicks a link in the spoofed email; (2) a five-stage redirect chain applies User-Agent fingerprinting, anti-analysis checks, and a CAPTCHA gate; (3) the victim reaches either an AiTM proxy or a device code endpoint; (4) in the AiTM path, credentials are proxied in real-time to Microsoft's legitimate authentication system, capturing the authenticated session cookie; (5) in the device code path, the victim is presented with a short authentication code and a plausible pretext to enter it on microsoft.com/devicelogin — the legitimate Microsoft device login portal — completing MFA themselves, at which point the attacker's polling loop captures the resulting access and refresh tokens. The device code variant is considered operationally cleaner for attackers as it requires no fake login page and fully satisfies MFA on the victim's side.

Post-compromise activity is methodical. Harvested tokens are replayed within minutes from dedicated proxy infrastructure on VPS and commercial VPN networks. One observed AiTM proxy IP (38.248.95.214) continued authenticating against a victim's account more than two weeks after the initial phishing campaign. Attackers perform device registration in Entra ID within minutes of gaining initial access to generate a Primary Refresh Token (PRT) — a credential that survives password resets and Microsoft's most common first-response action. Attackers then enumerate Microsoft Graph API resources systematically: Outlook mailboxes (email content), Teams conversations (chat history and channel data), SharePoint sites (document libraries), OneDrive files (personal cloud storage), contacts, calendars, and registered OAuth applications. A deliberate delay of several hours precedes the creation of malicious inbox rules and data exfiltration, reducing the likelihood of immediate detection. The compromised account's trust is then leveraged for cascaded phishing campaigns against partners, vendors, and third parties.

According to Sekoia.io's global analysis of AiTM phishing threats (January-April 2025), Greatness was ranked 8th among 11 tracked kits with a global score of 2.0/5, behind Tycoon 2FA (4.8), Storm-1167 (4.2), NakedPages (4.0), Sneaky 2FA (3.6), EvilProxy (3.2), Evilginx/ywnjb (3.2), and Saiga 2FA (2.0). Despite its lower ranking, the platform's sustained operation since mid-2022, integration of three distinct phishing modalities, and adaptation to the RingCentral breach nexus demonstrate ongoing threat relevance. The Cisco Talos IOC repository lists over 200 SHA256 hashes of phishing attachment payloads and hundreds of compromised domains hosting Greatness admin panels accessed via the path pattern */admin/js/mj.php.

The RingCentral nexus adds operational context. On July 27, 2026, the ShinyHunters threat group listed RingCentral on its dark web leak portal demanding contact by July 30. Following the deadline's passage, on August 3, 2026, ShinyHunters updated the listing claiming exfiltration of 623 GB of uncompressed data (280 GB compressed), including 21,969 end-user account records, 120 internal employee credentials, and 173 third-party employee credentials. The listing included an SHA-256 checksum but no published sample files. RingCentral has not issued an official breach notification, and the claims remain unconfirmed as of August 4, 2026. ZeroBEC researchers noted that attackers using Greatness may have obtained target lists from this breach data, but stated a connection cannot be confidently made. RingCentral customers are advised to treat the breach disclosure as a trigger to audit and tighten email exclusion rules for RingCentral's domains.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1566.001 Spearphishing Attachment
- T1199 Trusted Relationship
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1059.007 JavaScript
- T1557 Adversary-in-the-Middle
- T1528 Steal Application Access Token
- T1606.001 Web Cookies
- T1556.006 Multi-Factor Authentication
- T1070.006 Timestomp
- T1564.008 Email Hiding Rules
- T1078.004 Cloud Accounts
- T1098.005 Device Registration
- T1098.002 Additional Email Delegate Permissions
- T1087.004 Cloud Account
- T1069.003 Cloud Groups
- T1550.001 Application Access Token
- T1114.002 Remote Email Collection
- T1114.003 Email Forwarding Rule
- T1213.002 Sharepoint
- T1530 Data from Cloud Storage
- T1213.003 Code Repositories
- T1102.003 One-Way Communication
- T1090.002 External Proxy

## Sources

- [Phishing service spoofs RingCentral to steal Microsoft 365 accounts](https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/)
- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens](https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html)
- [New phishing-as-a-service tool 'Greatness' already seen in the wild](https://blog.talosintelligence.com/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild/)
- [New 'Greatness' Phishing-as-a-Service Targets Microsoft 365 Accounts](https://www.securityweek.com/new-greatness-phishing-as-a-service-targets-microsoft-365-accounts/)
- [ZeroBEC Research: Greatness PhaaS — AiTM and Device Code Phishing](https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing)
- [Tale of Greatness: Journey Through Dark Roads](https://www.trellix.com/blogs/research/tale-of-greatness-journey-through-dark-roads/)
- [Global analysis of Adversary-in-the-Middle phishing threats](https://blog.sekoia.io/global-analysis-of-adversary-in-the-middle-phishing-threats/)
- [Inside an AI-enabled device code phishing campaign](https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/)
- [Cisco Talos Greatness IOC Repository](https://github.com/Cisco-Talos/IOCs/blob/main/2023/04/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild.txt)
- [Device Code Flow: The Gift That Keeps on Giving — to Attackers](https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/device-code-flow-the-gift-that-keeps-on-giving-%E2%80%94-to-attackers/4540949)
- [ShinyHunters Allegedly Claims RingCentral Data Breach](https://cybersecuritytimes.com/hackers-allegedly-claim-ringcentral-data-breach/)
- [ShinyHunters adds EY, RingCentral, and Brinks Home to data leak site](https://breachnews.com/breaches/shinyhunters-adds-ey-ringcentral-and-brinks-home-to-data-leak-site/)
- [OAuth Device Code Phishing: 37x Surge in Enterprise ATO](https://labs.cloudsecurityalliance.org/research/csa-research-note-oauth-device-code-phishing-surge-20260405/)
- [Greatness PhaaS Platform on ANY.RUN Malware Trends](https://any.run/malware-trends/greatness/)
- [Realt Hacker News: Greatness PhaaS Adds Device Code Phishing](https://realhacker.news/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1871
