# Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaigns

> Greatness is a sophisticated phishing-as-a-service (PhaaS) platform employing adversary-in-the-middle (AiTM) relay and device code phishing to defeat MFA and capture authentication tokens for Microsoft 365, iCloud, Yahoo, and Google Workspace. Recent campaigns use spoofed RingCentral voicemail and performance-review lures delivered via safe-sender exclusion bypasses that override SPF/DKIM/DMARC failures.

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1895
- **ID:** TL-2026-1895
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Greatness is a commercial phishing-as-a-service (PhaaS) platform first observed in mid-2022 and publicly documented by Cisco Talos in May 2023. Originally targeting exclusively Microsoft 365 business users, it has since expanded to support iCloud, Yahoo, and Google Workspace credential theft. The platform is distributed via a Telegram channel (@GreatnessPage) with over 3,250 subscribers and priced at $289 per month with a one-day free trial, operators register through a dedicated Telegram bot (@gr8managerbot) and receive license keys from the @greatnessmgr developer account.

The core attack mechanism is an adversary-in-the-middle (AiTM) proxy that sits between the victim's browser and the legitimate identity provider. When a victim visits the phishing page — which displays their real organization logo and background extracted from the actual Microsoft 365 login page — the Greatness backend relays credentials and MFA challenges in real time to Microsoft's genuine authentication servers. Because the proxy completes the full MFA flow (including Microsoft Authenticator push notifications, number matching, and SMS codes), it captures a fully authenticated session cookie and refresh tokens, completely bypassing MFA. The stolen token is replayed from attacker-controlled infrastructure (VPS and commercial VPN services including ExpressVPN, EventVPN/Netshield, and PIA), meaning impossible-travel detection rules fail to trigger.

In 2025, Greatness added an alternative attack vector: OAuth 2.0 device code phishing. This abuses the Device Authorization Grant flow, presenting victims with a plausible pretext to enter a short code on the legitimate Microsoft login page. Because the victim authenticates directly on Microsoft's real infrastructure, nothing visually appears wrong, making detection extremely difficult for users. The platform offers 11+ downloadable lure templates including voicemail notifications, document sharing invites, QR codes, video players, chat assistance pretexts, and OneDrive file-sharing lures.

The observed campaign in August 2026 used spoofed RingCentral voicemail messages and performance-review emails. Emails originated from an IONOS mail server (212.227.146.181) with a spoofed sender address (service@ringcentral.com) and subjects including 'Action required: Review your performance appraisal' and 'URGENT: Your Performance Review is Ready.' All four observed phishing emails failed SPF, DKIM, and DMARC checks, yet were delivered to recipients' inboxes because the target organization had added RingCentral's domain to safe-sender exclusions — a domain-based whitelist that overrides authentication failures. The emails carried a fraudulent banner falsely claiming verification by the organization's safe-senders list and achieved a Spam Confidence Level (SCL) of -1 (safe) in Microsoft Exchange. ZeroBEC detected the campaign through behavioral analysis of sender-link domain mismatches rather than relying on authentication results.

The redirect chain progresses through multiple stages: initial click-tracking (searchbriefing.com), an anti-analysis redirector (loading.finreportviewersoftware.sbs) that checks for headless browsers and automated visitors, an operator API gateway (api-[token].onewayoutlook.one) that maintains a humanScore and can require Cloudflare Turnstile-style verification, and finally the AiTM phishing page. The platform operator dashboard exposes campaign statistics, a heat map of victims, domain configuration, CAPTCHA selection, background theme options, and cookie storage configuration.

Post-compromise, attackers replay tokens within minutes from dedicated proxy infrastructure. They enumerate victim resources via Microsoft Graph API (Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and OAuth application registrations), register new devices to generate Primary Refresh Tokens (PRTs) for long-term persistence, and wait several hours before setting up malicious inbox rules or exfiltrating data to evade detection. One observed AiTM proxy IP (38.248.95.214) was still actively authenticating against the victim's account more than two weeks after the initial phishing email. The RingCentral data breach claimed by ShinyHunters (July 27, 2026, with 623GB of allegedly stolen data) may have provided Greatness operators with validated target lists, though no definitive link has been established.

Defenders must revoke all active and refresh tokens in Entra ID upon compromise — credential rotation alone is insufficient because existing tokens remain valid. Domain-based safe-sender exclusions should be replaced with authentication-conditional rules requiring SPF/DKIM/DMARC pass. Organizations should block the device code authentication flow globally in Conditional Access policies, move to phishing-resistant MFA (FIDO2/Windows Hello for Business), and continuously audit OAuth consent grants and Microsoft Graph Activity.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1078 Valid Accounts
- T1505 Server Software Component
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1056 Input Capture
- T1539 Steal Web Session Cookie
- T1087 Account Discovery
- T1614 System Location Discovery
- T1114 Email Collection
- T1119 Automated Collection
- T1071 Application Layer Protocol

## Sources

- [ZeroBEC In-Depth Analysis: Inside Greatness PhaaS](https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing)
- [Greatness PhaaS — Cybersecurity News Report](https://cybersecuritynews.com/greatness-phaas/)
- [Phishing Service Spoofs RingCentral to Steal Microsoft 365 Accounts](https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/)
- [Greatness PhaaS Adds Device Code Phishing Capabilities](https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html)
- [Cisco Talos: New PhaaS Tool 'Greatness' Already Seen in the Wild](https://blog.talosintelligence.com/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild/)
- [Cisco Talos Greatness IOCs (GitHub)](https://github.com/Cisco-Talos/IOCs/blob/main/2023/04/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild.txt)
- [Greatness Phishing Kit PHP Code Deep-Dive](https://rmceoin.github.io/malware-analysis/2023/04/05/greatness.html)
- [Hornet Security: Greatness Phishing-as-a-Service Analysis](https://www.hornetsecurity.com/en/blog/greatness-phishing-as-a-service/)
- [RingCentral Data Breach Alleged by ShinyHunters](https://cybersecuritytimes.com/hackers-allegedly-claim-ringcentral-data-breach/)
- [New Greatness Service Simplifies Microsoft 365 Phishing](https://www.bleepingcomputer.com/news/security/new-greatness-service-simplifies-microsoft-365-phishing-attacks/)
- [Microsoft 365 Users Hit by Phishing Scheme Posing as RingCentral](https://www.techradar.com/pro/security/microsoft-365-users-hit-by-phishing-scheme-posing-as-ringcentral-emails)
- [WMC Global 2022 Year in Review — Greatness/Boss](https://www.wmcglobal.com/blog/2022-year-in-review)
- [ShinyHunters Adds RingCentral, EY, Brink's Home to Data Leak Site](https://breachnews.com/breaches/shinyhunters-adds-ey-ringcentral-and-brinks-home-to-data-leak-site/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1895
