Cybercriminals have been using a sophisticated phishing-as-a-service (PhaaS) platform called Greatness to steal Microsoft 365 account credentials, and their tactics just got even more insidious. The platform has evolved over the years to target multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace, with its operators abusing trusted communications platforms like RingCentral to evade email security filters.
The latest campaign observed by researchers at ZeroBEC involved Greatness operators impersonating RingCentral’s service emails, claiming they came from a legitimate address (service@ringcentral[.]com), to target actual users of the service. The emails were designed to look like voicemail and performance-review notifications, luring recipients into opening them. What’s alarming is that despite failing SPF and DMARC checks, and lacking a DKIM signature, these emails were still accepted by receiving systems because RingCentral was whitelisted.
But here’s the catch: these emails included a fake banner claiming the sender had been verified by the organization’s safe-sender list, which reduced suspicion among recipients. The tactic allowed Greatness to bypass normal email filtering stages and achieve a Spam Confidence Level (SCL) of -1 on Microsoft Exchange. This means that even with robust security measures in place, these emails were still able to slip through undetected.
When victims clicked the button embedded in those emails, they were routed to the Greatness infrastructure, where their MFA-approved authentication tokens were captured either through an adversary-in-the-middle (AiTM) phishing flow or a device-code phishing flow. Post-compromise, the attackers replayed Microsoft 365 authentication tokens from compromised VPS and commercial VPN infrastructure to access the affected accounts. The consequences? Enumerating Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications through Microsoft Graph, with access persisting for more than two weeks in some cases.
It’s worth noting that RingCentral recently disclosed a data breach incident claimed by threat actor ShinyHunters, which may have provided cybercriminals using Greatness with a list of valid targets – users of the RingCentral platform. While a connection cannot be confidently made, it highlights the potential for compromised data to be used in phishing campaigns.
So what can organizations do to protect themselves? ZeroBEC recommends auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication. They also advise hunting for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses. If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.
The key takeaway here is that security teams must stay vigilant and test every layer of their defenses before attackers do. As the Picus whitepaper shows, breach and attack simulation tests can help identify weaknesses in SIEM and EDR rules, preventing threats from slipping through undetected. With Greatness operators constantly evolving their tactics, it’s essential for organizations to prioritize email security, authentication protocols, and continuous monitoring to stay ahead of these sophisticated attacks.
Source: Bleeping Computer — 2026-08-04