Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaigns — Threadlinqs Intelligence
As of 2026-08-05, Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaigns is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1895 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Greatness is a sophisticated phishing-as-a-service (PhaaS) platform employing adversary-in-the-middle (AiTM) relay and device code phishing to defeat MFA and capture authentication tokens for
Greatness is a commercial phishing-as-a-service (PhaaS) platform first observed in mid-2022 and publicly documented by Cisco Talos in May 2023. Originally targeting exclusively Microsoft 365 business users, it has since expanded to support iCloud, Yahoo, and Google Workspace credential theft. The platform is distributed via a Telegram channel (@GreatnessPage) with over 3,250 subscribers and priced at $289 per month with a one-day free trial, operators register through a dedicated Telegram bot (@gr8managerbot) and receive license keys from the @greatnessmgr developer account.
The core attack mechanism is an adversary-in-the-middle (AiTM) proxy that sits between the victim's browser and the legitimate identity provider. When a victim visits the phishing page — which displays their real organization logo and background extracted from the actual Microsoft 365 login page — the Greatness backend relays credentials and MFA challenges in real time to Microsoft's genuine authentication servers. Because the proxy completes the full MFA flow (including Microsoft Authenticator push notifications, number matching, and SMS codes), it captures a fully authenticated session cookie and refresh tokens, completely bypassing MFA. The stolen token is replayed from attacker-controlled infrastructure (VPS and commercial VPN services including ExpressVPN, EventVPN/Netshield, and PIA), meaning impossible-travel detection rules fail to trigger.
In 2025, Greatness added an alternative attack vector: OAuth 2.0 device code phishing. This abuses the Device Authorization Grant flow, presenting victims with a plausible pretext to enter a short code on the legitimate Microsoft login page. Because the victim authenticates directly on Microsoft's real infrastructure, nothing visually appears wrong, making detection extremely difficult for users. The platform offers 11+ downloadable lure templates including voicemail notifications, document sharing invites, QR codes, video players, chat assistance pretexts, and OneDrive file-sharing lures.
The observed campaign in August 2026 used spoofed RingCentral voicemail messages and performance-review emails. Emails originated from an IONOS mail server (212.227.146.181) with a spoofed sender address (service@ringcentral.com) and subjects including 'Action required: Review your performance appraisal' and 'URGENT: Your Performance Review is Ready.' All four observed phishing emails failed SPF, DKIM, and DMARC checks, yet were delivered to recipients' inboxes because the target organization had added RingCentral's domain to safe-sender exclusions — a domain-based whitelist that overrides authentication failures. The emails carried a fraudulent banner falsely claiming verification by the organization's safe-senders list and achieved a Spam Confidence Level (SCL) of -1 (safe) in Microsoft Exchange. ZeroBEC detected the campaign through behavioral analysis of sender-link domain mismatches rather than relying on authentication results.
The redirect chain progresses through multiple stages: initial click-tracking (searchbriefing.com), an anti-analysis redirector (loading.finreportviewersoftware.sbs) that checks for headless browsers and automated visitors, an operator API gateway (api-[token].onewayoutlook.one) that maintains a humanScore and can require Cloudflare Turnstile-style verification, and finally the AiTM phishing page. The platform operator dashboard exposes campaign statistics, a heat map of victims, domain configuration, CAPTCHA selection, background theme options, and cookie storage configuration.
Post-compromise, attackers replay tokens within minutes from dedicated proxy infrastructure. They enumerate victim resources via Microsoft Graph API (Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and OAuth application registrations), register new devices to generate Primary Refresh Tokens (PRTs) for long-term persistence, and wait several hours before setting up malicio
Target sectors: manufacturing, health, technology, real-estate, education, finance, government administration, business-services
Target regions: North America, Europe, united kingdom, australia, south africa
Detections & IOCs
As of 2026-08-05, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1078, T1505, T1027, T1140, T1497, T1056, T1539, T1087