Threat reportPhishingTL-2026-1895

Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaigns

highACTIVE

Greatness PhaaS (TL-2026-1895), also tracked as Greatness PhaaS, is a high-severity phishing campaign, first published 2026-08-05. It has no confirmed attribution, affects Microsoft Microsoft 365 (Entra ID / Azure AD), maps to 14 MITRE ATT&CK techniques (T1027, T1056, T1071), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1895

Threat ID
TL-2026-1895
Also known as
Greatness PhaaS, Greatness AiTM Phishing Kit, Greatness Phishing-as-a-Service
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Motivation
FINANCIAL
Target sectors
manufacturing, health, technology, real-estate, education, finance, government administration, business-services
Target regions
North America, Europe, united kingdom, australia, south africa
Detection rules
9
Indicators of compromise
27

Malware and tooling in Greatness PhaaS

Malware and tooling: telegram

How Greatness PhaaS works

Greatness is a sophisticated phishing-as-a-service (PhaaS) platform employing adversary-in-the-middle (AiTM) relay and device code phishing to defeat MFA and capture authentication tokens for Microsoft 365, iCloud, Yahoo, and Google Workspace. Recent campaigns use spoofed RingCentral voicemail and performance-review lures delivered via safe-sender exclusion bypasses that override SPF/DKIM/DMARC failures.

Greatness is a commercial phishing-as-a-service (PhaaS) platform first observed in mid-2022 and publicly documented by Cisco Talos in May 2023. Originally targeting exclusively Microsoft 365 business users, it has since expanded to support iCloud, Yahoo, and Google Workspace credential theft. The platform is distributed via a Telegram channel (@GreatnessPage) with over 3,250 subscribers and priced at $289 per month with a one-day free trial, operators register through a dedicated Telegram bot (@gr8managerbot) and receive license keys from the @greatnessmgr developer account.

The core attack mechanism is an adversary-in-the-middle (AiTM) proxy that sits between the victim's browser and the legitimate identity provider. When a victim visits the phishing page — which displays their real organization logo and background extracted from the actual Microsoft 365 login page — the Greatness backend relays credentials and MFA challenges in real time to Microsoft's genuine authentication servers. Because the proxy completes the full MFA flow (including Microsoft Authenticator push notifications, number matching, and SMS codes), it captures a fully authenticated session cookie and refresh tokens, completely bypassing MFA. The stolen token is replayed from attacker-controlled infrastructure (VPS and commercial VPN services including ExpressVPN, EventVPN/Netshield, and PIA), meaning impossible-travel detection rules fail to trigger.

In 2025, Greatness added an alternative attack vector: OAuth 2.0 device code phishing. This abuses the Device Authorization Grant flow, presenting victims with a plausible pretext to enter a short code on the legitimate Microsoft login page. Because the victim authenticates directly on Microsoft's real infrastructure, nothing visually appears wrong, making detection extremely difficult for users. The platform offers 11+ downloadable lure templates including voicemail notifications, document sharing invites, QR codes, video players, chat assistance pretexts, and OneDrive file-sharing lures.

The observed campaign in August 2026 used spoofed RingCentral voicemail messages and performance-review emails. Emails originated from an IONOS mail server (212.227.146.181) with a spoofed sender address (service@ringcentral.com) and subjects including 'Action required: Review your performance appraisal' and 'URGENT: Your Performance Review is Ready.' All four observed phishing emails failed SPF, DKIM, and DMARC checks, yet were delivered to recipients' inboxes because the target organization had added RingCentral's domain to safe-sender exclusions — a domain-based whitelist that overrides authentication failures. The emails carried a fraudulent banner falsely claiming verification by the organization's safe-senders list and achieved a Spam Confidence Level (SCL) of -1 (safe) in Microsoft Exchange. ZeroBEC detected the campaign through behavioral analysis of sender-link domain mismatches rather than relying on authentication results.

The redirect chain progresses through multiple stages: initial click-tracking (searchbriefing.com), an anti-analysis redirector (loading.finreportviewersoftware.sbs) that checks for headless browsers and automated visitors, an operator API gateway (api-[token].onewayoutlook.one) that maintains a humanScore and can require Cloudflare Turnstile-style verification, and finally the AiTM phishing page. The platform operator dashboard exposes campaign statistics, a heat map of victims, domain configuration, CAPTCHA selection, background theme options, and cookie storage configuration.

Post-compromise, attackers replay tokens within minutes from dedicated proxy infrastructure. They enumerate victim resources via Microsoft Graph API (Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and OAuth application registrations), register new devices to generate Primary Refresh Tokens (PRTs) for long-term persistence, and wait several hours before setting up malicious inbox rules or exfiltrating data to evade detection. One observed AiTM proxy IP (38.248.95.214) was still actively authenticating against the victim's account more than two weeks after the initial phishing email. The RingCentral data breach claimed by ShinyHunters (July 27, 2026, with 623GB of allegedly stolen data) may have provided Greatness operators with validated target lists, though no definitive link has been established.

Defenders must revoke all active and refresh tokens in Entra ID upon compromise — credential rotation alone is insufficient because existing tokens remain valid. Domain-based safe-sender exclusions should be replaced with authentication-conditional rules requiring SPF/DKIM/DMARC pass. Organizations should block the device code authentication flow globally in Conditional Access policies, move to phishing-resistant MFA (FIDO2/Windows Hello for Business), and continuously audit OAuth consent grants and Microsoft Graph Activity.

MITRE ATT&CK techniques used in TL-2026-1895

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie

Command and Control

T1071 Application Layer Protocol

Persistence

T1078 Valid Accounts; T1505 Server Software Component

Discovery

T1087 Account Discovery; T1614 System Location Discovery

Collection

T1114 Email Collection; T1119 Automated Collection

Execution

T1204 User Execution

Initial Access

T1566 Phishing

Affected products and versions in Greatness PhaaS

  • Microsoft — Microsoft 365 (Entra ID / Azure AD)
    Vulnerable versions: All versions using password-based authentication with OAuth tokens
  • Apple — iCloud / Apple ID
    Vulnerable versions: All versions with password-based authentication
  • Yahoo — Yahoo Mail / Yahoo ID
    Vulnerable versions: All versions with password-based authentication
  • Google — Google Workspace / Google Account
    Vulnerable versions: All versions with password-based authentication

Remediation for Greatness PhaaS

Immediate actions

  • Revoke all active tokens and refresh tokens in Entra ID for compromised accounts — credential rotation alone is insufficient
  • Audit and replace domain-based safe-sender exclusions with authentication-conditional rules requiring SPF/DKIM/DMARC pass
  • Block known IoC domains and proxy IPs at network perimeter and email gateway
  • Block device code authentication flow globally in Conditional Access policies

Workarounds

  • Enforce email authentication (SPF/DKIM/DMARC) pass as prerequisite for safe-sender delivery
  • Treat vendor breach disclosures as triggers to immediately audit email exclusion rules
  • Monitor MFA-approved logins from hosting provider IPs or commercial VPN infrastructure
  • Review OAuth application consents and Microsoft Graph API activity regularly
  • Search for Laravel session cookies (laravelsession, XSRF-TOKEN) across HTTP traffic as hunting fingerprint

Longer-term hardening

  • Deploy phishing-resistant MFA methods (FIDO2/Windows Hello for Business)
  • Implement token protection policies in Entra ID to bind tokens to specific devices
  • Establish vendor breach notification review process for email trust configurations
  • Deploy behavioral email security analysis capable of detecting sender-link domain mismatches
  • Implement Continuous Access Evaluation (CAE) to reduce token replay window

Timeline of Greatness PhaaS

  • Earliest mj.js JavaScript component observed via URLScan.io, indicating Greatness kit in early development and deployment
  • Analysis of later mj.js variant reveals compromised WordPress infrastructure used to host Greatness PHP components
  • Benefit.html phishing lure analyzed by JOESandbox, showing obfuscated JavaScript decoder loading remote mj.js payload
  • Notable spike in Greatness campaign activity observed by Cisco Talos, documented by WMC Global year-in-review
  • Second major activity spike detected by Cisco Talos, with increased targeting of US, UK, Australian, and Canadian organizations
  • Independent security researcher publishes detailed PHP code analysis of Greatness kit, documenting central API at dyno44.herokuapp.com and ~10% credential success rate
  • Cisco Talos and BleepingComputer publicly disclose Greatness PhaaS platform; kit priced at $120/month at this time
  • Greatness subscription price reported at $120/month with platform continuing active development
  • Device code phishing capability added; multi-platform support expanded to include iCloud, Yahoo, and Google Workspace alongside original M365 targeting; price increased to $289/month
  • ShinyHunters claims RingCentral data breach, listing company on dark web leak site alongside EY and Brink's Home; potential source of validated target lists for Greatness campaigns
  • ShinyHunters deadline for RingCentral negotiation passes without confirmed resolution; breach claims escalate
  • ShinyHunters updates RingCentral listing claiming 623GB of uncompressed data exfiltrated, including 21,969 end-user account records and 120 internal employee credentials
  • ZeroBEC publishes analysis of active Greatness RingCentral spoofing campaign: AiTM proxy IP still authenticating 2+ weeks post-compromise, safe-sender bypass confirmed, shared backend infrastructure documented with 14+ domains and operator tokens

Sources cited for Greatness PhaaS

Detection coverage for TL-2026-1895

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1895 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats