Threat reportPhishingTL-2026-1895
Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaigns
Greatness PhaaS (TL-2026-1895), also tracked as Greatness PhaaS, is a high-severity phishing campaign, first published 2026-08-05. It has no confirmed attribution, affects Microsoft Microsoft 365 (Entra ID / Azure AD), maps to 14 MITRE ATT&CK techniques (T1027, T1056, T1071), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1895
- Threat ID
- TL-2026-1895
- Also known as
- Greatness PhaaS, Greatness AiTM Phishing Kit, Greatness Phishing-as-a-Service
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, health, technology, real-estate, education, finance, government administration, business-services
- Target regions
- North America, Europe, united kingdom, australia, south africa
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Greatness PhaaS
Malware and tooling: telegram
How Greatness PhaaS works
Greatness is a sophisticated phishing-as-a-service (PhaaS) platform employing adversary-in-the-middle (AiTM) relay and device code phishing to defeat MFA and capture authentication tokens for Microsoft 365, iCloud, Yahoo, and Google Workspace. Recent campaigns use spoofed RingCentral voicemail and performance-review lures delivered via safe-sender exclusion bypasses that override SPF/DKIM/DMARC failures.
Greatness is a commercial phishing-as-a-service (PhaaS) platform first observed in mid-2022 and publicly documented by Cisco Talos in May 2023. Originally targeting exclusively Microsoft 365 business users, it has since expanded to support iCloud, Yahoo, and Google Workspace credential theft. The platform is distributed via a Telegram channel (@GreatnessPage) with over 3,250 subscribers and priced at $289 per month with a one-day free trial, operators register through a dedicated Telegram bot (@gr8managerbot) and receive license keys from the @greatnessmgr developer account.
The core attack mechanism is an adversary-in-the-middle (AiTM) proxy that sits between the victim's browser and the legitimate identity provider. When a victim visits the phishing page — which displays their real organization logo and background extracted from the actual Microsoft 365 login page — the Greatness backend relays credentials and MFA challenges in real time to Microsoft's genuine authentication servers. Because the proxy completes the full MFA flow (including Microsoft Authenticator push notifications, number matching, and SMS codes), it captures a fully authenticated session cookie and refresh tokens, completely bypassing MFA. The stolen token is replayed from attacker-controlled infrastructure (VPS and commercial VPN services including ExpressVPN, EventVPN/Netshield, and PIA), meaning impossible-travel detection rules fail to trigger.
In 2025, Greatness added an alternative attack vector: OAuth 2.0 device code phishing. This abuses the Device Authorization Grant flow, presenting victims with a plausible pretext to enter a short code on the legitimate Microsoft login page. Because the victim authenticates directly on Microsoft's real infrastructure, nothing visually appears wrong, making detection extremely difficult for users. The platform offers 11+ downloadable lure templates including voicemail notifications, document sharing invites, QR codes, video players, chat assistance pretexts, and OneDrive file-sharing lures.
The observed campaign in August 2026 used spoofed RingCentral voicemail messages and performance-review emails. Emails originated from an IONOS mail server (212.227.146.181) with a spoofed sender address (service@ringcentral.com) and subjects including 'Action required: Review your performance appraisal' and 'URGENT: Your Performance Review is Ready.' All four observed phishing emails failed SPF, DKIM, and DMARC checks, yet were delivered to recipients' inboxes because the target organization had added RingCentral's domain to safe-sender exclusions — a domain-based whitelist that overrides authentication failures. The emails carried a fraudulent banner falsely claiming verification by the organization's safe-senders list and achieved a Spam Confidence Level (SCL) of -1 (safe) in Microsoft Exchange. ZeroBEC detected the campaign through behavioral analysis of sender-link domain mismatches rather than relying on authentication results.
The redirect chain progresses through multiple stages: initial click-tracking (searchbriefing.com), an anti-analysis redirector (loading.finreportviewersoftware.sbs) that checks for headless browsers and automated visitors, an operator API gateway (api-[token].onewayoutlook.one) that maintains a humanScore and can require Cloudflare Turnstile-style verification, and finally the AiTM phishing page. The platform operator dashboard exposes campaign statistics, a heat map of victims, domain configuration, CAPTCHA selection, background theme options, and cookie storage configuration.
Post-compromise, attackers replay tokens within minutes from dedicated proxy infrastructure. They enumerate victim resources via Microsoft Graph API (Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and OAuth application registrations), register new devices to generate Primary Refresh Tokens (PRTs) for long-term persistence, and wait several hours before setting up malicious inbox rules or exfiltrating data to evade detection. One observed AiTM proxy IP (38.248.95.214) was still actively authenticating against the victim's account more than two weeks after the initial phishing email. The RingCentral data breach claimed by ShinyHunters (July 27, 2026, with 623GB of allegedly stolen data) may have provided Greatness operators with validated target lists, though no definitive link has been established.
Defenders must revoke all active and refresh tokens in Entra ID upon compromise — credential rotation alone is insufficient because existing tokens remain valid. Domain-based safe-sender exclusions should be replaced with authentication-conditional rules requiring SPF/DKIM/DMARC pass. Organizations should block the device code authentication flow globally in Conditional Access policies, move to phishing-resistant MFA (FIDO2/Windows Hello for Business), and continuously audit OAuth consent grants and Microsoft Graph Activity.
MITRE ATT&CK techniques used in TL-2026-1895
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie
Command and Control
T1071 Application Layer Protocol
Persistence
T1078 Valid Accounts; T1505 Server Software Component
Discovery
T1087 Account Discovery; T1614 System Location Discovery
Collection
T1114 Email Collection; T1119 Automated Collection
Execution
Initial Access
Affected products and versions in Greatness PhaaS
- Microsoft — Microsoft 365 (Entra ID / Azure AD)
Vulnerable versions: All versions using password-based authentication with OAuth tokens - Apple — iCloud / Apple ID
Vulnerable versions: All versions with password-based authentication - Yahoo — Yahoo Mail / Yahoo ID
Vulnerable versions: All versions with password-based authentication - Google — Google Workspace / Google Account
Vulnerable versions: All versions with password-based authentication
Remediation for Greatness PhaaS
Immediate actions
- Revoke all active tokens and refresh tokens in Entra ID for compromised accounts — credential rotation alone is insufficient
- Audit and replace domain-based safe-sender exclusions with authentication-conditional rules requiring SPF/DKIM/DMARC pass
- Block known IoC domains and proxy IPs at network perimeter and email gateway
- Block device code authentication flow globally in Conditional Access policies
Workarounds
- Enforce email authentication (SPF/DKIM/DMARC) pass as prerequisite for safe-sender delivery
- Treat vendor breach disclosures as triggers to immediately audit email exclusion rules
- Monitor MFA-approved logins from hosting provider IPs or commercial VPN infrastructure
- Review OAuth application consents and Microsoft Graph API activity regularly
- Search for Laravel session cookies (laravelsession, XSRF-TOKEN) across HTTP traffic as hunting fingerprint
Longer-term hardening
- Deploy phishing-resistant MFA methods (FIDO2/Windows Hello for Business)
- Implement token protection policies in Entra ID to bind tokens to specific devices
- Establish vendor breach notification review process for email trust configurations
- Deploy behavioral email security analysis capable of detecting sender-link domain mismatches
- Implement Continuous Access Evaluation (CAE) to reduce token replay window
Timeline of Greatness PhaaS
- Earliest mj.js JavaScript component observed via URLScan.io, indicating Greatness kit in early development and deployment
- Analysis of later mj.js variant reveals compromised WordPress infrastructure used to host Greatness PHP components
- Benefit.html phishing lure analyzed by JOESandbox, showing obfuscated JavaScript decoder loading remote mj.js payload
- Notable spike in Greatness campaign activity observed by Cisco Talos, documented by WMC Global year-in-review
- Second major activity spike detected by Cisco Talos, with increased targeting of US, UK, Australian, and Canadian organizations
- Independent security researcher publishes detailed PHP code analysis of Greatness kit, documenting central API at dyno44.herokuapp.com and ~10% credential success rate
- Cisco Talos and BleepingComputer publicly disclose Greatness PhaaS platform; kit priced at $120/month at this time
- Greatness subscription price reported at $120/month with platform continuing active development
- Device code phishing capability added; multi-platform support expanded to include iCloud, Yahoo, and Google Workspace alongside original M365 targeting; price increased to $289/month
- ShinyHunters claims RingCentral data breach, listing company on dark web leak site alongside EY and Brink's Home; potential source of validated target lists for Greatness campaigns
- ShinyHunters deadline for RingCentral negotiation passes without confirmed resolution; breach claims escalate
- ShinyHunters updates RingCentral listing claiming 623GB of uncompressed data exfiltrated, including 21,969 end-user account records and 120 internal employee credentials
- ZeroBEC publishes analysis of active Greatness RingCentral spoofing campaign: AiTM proxy IP still authenticating 2+ weeks post-compromise, safe-sender bypass confirmed, shared backend infrastructure documented with 14+ domains and operator tokens
Sources cited for Greatness PhaaS
- ZeroBEC In-Depth Analysis: Inside Greatness PhaaS
- Greatness PhaaS — Cybersecurity News Report
- Phishing Service Spoofs RingCentral to Steal Microsoft 365 Accounts
- Greatness PhaaS Adds Device Code Phishing Capabilities
- Cisco Talos: New PhaaS Tool 'Greatness' Already Seen in the Wild
- Cisco Talos Greatness IOCs (GitHub)
- Greatness Phishing Kit PHP Code Deep-Dive
- Hornet Security: Greatness Phishing-as-a-Service Analysis
- RingCentral Data Breach Alleged by ShinyHunters
- New Greatness Service Simplifies Microsoft 365 Phishing
- Microsoft 365 Users Hit by Phishing Scheme Posing as RingCentral
- WMC Global 2022 Year in Review — Greatness/Boss
- ShinyHunters Adds RingCentral, EY, Brink's Home to Data Leak Site
Detection coverage for TL-2026-1895
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1895 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.