Listen to this Post
Introduction: When Trust Becomes the Attacker’s Most Powerful Tool
Phishing attacks are no longer limited to poorly written emails, suspicious links, and fake login pages. Modern phishing operations increasingly behave like commercial technology businesses, offering subscription plans, technical support, reusable infrastructure, and continuously updated attack features. The evolution of the Greatness phishing-as-a-service (PhaaS) platform is a clear example of this transformation.
Active since at least mid-2022, Greatness has developed from a credential-harvesting toolkit into a more advanced phishing ecosystem capable of conducting adversary-in-the-middle (AiTM) attacks, stealing authenticated Microsoft 365 sessions, and abusing device-code authentication flows. Its operators have also expanded beyond Microsoft 365, building phishing templates and infrastructure aimed at users of iCloud, Yahoo, and Google Workspace.
The latest activity observed by email-security researchers at ZeroBEC shows how attackers are combining technical deception with organizational trust. Instead of relying only on spoofed brands, the campaign reportedly abused trust associated with the RingCentral communications platform to help malicious emails bypass security controls and appear legitimate to users.
The danger is not simply that attackers can imitate a trusted company. The more serious issue is that trusted domains, safe-sender lists, and security exceptions can become pathways through which malicious messages receive less scrutiny. Once an attacker reaches a victim’s Microsoft 365 account, the consequences may extend far beyond a stolen password, potentially exposing email, Teams conversations, SharePoint data, OneDrive files, calendars, contacts, and connected applications.
The Original Report in Summary
Greatness is a subscription-based phishing platform reportedly sold to cybercriminals for approximately $289 per month through a Telegram channel with thousands of subscribers. The service has targeted Microsoft 365 users in the United States, Canada, the United Kingdom, Australia, and South Africa and has expanded to support phishing campaigns against several major online platforms.
In a recently observed campaign, attackers used fake RingCentral-themed notifications, including voicemail alerts and performance-review messages. The emails appeared to impersonate RingCentral and used a sender identity resembling service@ringcentral[.]com.
According to ZeroBEC, the messages originated from an unknown IONOS mail server and reportedly failed SPF and DMARC checks while lacking a valid DKIM signature. Despite these warning signs, the emails were accepted because the RingCentral domain had been placed on an allowlist or trusted-sender configuration.
The campaign also included a misleading banner claiming that the sender had been verified through the organization’s safe-sender list. This added a human-focused layer of deception by making recipients believe that the message had already passed an internal security review.
The malicious emails reportedly achieved a Spam Confidence Level (SCL) of -1 in Microsoft Exchange, allowing them to avoid normal filtering stages. Victims who clicked the embedded button were redirected to Greatness-controlled infrastructure and placed into either an AiTM phishing flow or a device-code phishing flow.
After gaining access, attackers allegedly replayed Microsoft 365 authentication tokens from virtual private servers and commercial VPN infrastructure. They then explored Microsoft 365 resources through Microsoft Graph, including Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications. In some cases, access reportedly remained active for more than two weeks.
The Greatness Platform Has Become a Cybercrime Subscription Business
A Commercial Model for Phishing
Phishing-as-a-service platforms reduce the technical expertise required to launch sophisticated attacks. Instead of building phishing pages, hosting infrastructure, authentication bypass mechanisms, and campaign-management systems from scratch, criminals can rent a ready-made toolkit.
Greatness reportedly operates through a monthly subscription model priced at around $289. That price may appear relatively low when compared with the potential value of a compromised business account. A single successful Microsoft 365 takeover could provide access to confidential communications, financial information, customer records, internal documents, and additional identities inside an organization.
The subscription model also creates an incentive for operators to improve their product continuously. If customers pay every month, the platform must remain effective as Microsoft, email-security vendors, and enterprise defenders update their protections.
Cybercrime Platforms Are Adopting Software-Business Practices
The growth of PhaaS reflects a wider shift in cybercrime. Attackers increasingly use business-like models that resemble legitimate software-as-a-service operations. They may provide templates, updates, technical support, documentation, customer communities, and new features.
This structure separates phishing operations into specialized roles. One group develops the platform, another sells access, and subscribers conduct campaigns. The result is an ecosystem in which sophisticated attacks can be deployed by criminals who may not understand the underlying authentication technology.
That division of labor makes phishing more scalable and more difficult to disrupt. Removing one phishing website may have limited impact when the underlying service can generate new pages, domains, and campaigns quickly.
From Password Theft to Authentication-Session Theft
Why Passwords Are No Longer the Only Target
Traditional phishing pages attempt to collect usernames and passwords. However, password theft has become less reliable as organizations adopt multi-factor authentication.
Greatness has reportedly evolved toward AiTM attacks designed to capture authenticated sessions rather than only login credentials. This approach can place the attacker between the victim and the legitimate authentication service.
The victim may enter valid credentials, complete an MFA challenge, and believe the login succeeded normally. Meanwhile, the attacker may capture session information or authentication tokens that can be reused to access the account.
MFA Can Be Bypassed When the Session Is Stolen
Multi-factor authentication remains an important security control, but it is not a complete defense against every phishing technique. AiTM attacks can target the authenticated session that exists after MFA approval.
This distinction is critical. MFA protects against many attacks involving stolen passwords, but if an attacker obtains a valid session token, the attacker may not need to repeatedly enter the password or trigger another MFA request.
Organizations should therefore move toward phishing-resistant authentication methods where possible. Hardware-backed security keys, passkeys, and certificate-based authentication can provide stronger protection against many credential-relay attacks.
Device-Code Phishing Adds Another Dangerous Path
How Device-Code Abuse Works
Device-code authentication is designed to help users sign in on devices that have limited input capabilities. A service displays a code, and the user enters it through a browser or trusted authentication page.
Attackers can abuse this workflow by convincing a victim to enter an attacker-generated device code. The victim may believe they are approving access to a legitimate application or completing a required security action.
If the victim completes the process, the attacker may receive an authenticated session or authorization associated with the victim’s account.
The Attack Relies on Social Engineering
The technical process is only one part of the attack. The attacker still needs a convincing story. Fake voicemail notifications, account warnings, document-sharing requests, or urgent business messages can create pressure and encourage users to act before verifying the request.
This makes user awareness important, but awareness alone is not enough. Employees cannot be expected to detect every advanced authentication trick, especially when messages appear to come from trusted services.
Security controls should prevent dangerous authentication flows from being approved in the first place.
RingCentral Branding Was Used to Exploit Existing Trust
A Trusted Brand Can Become a Security Blind Spot
RingCentral is widely used by organizations for cloud calling, messaging, video communication, and voicemail services. Because many businesses depend on these tools, notifications related to missed calls or voicemail may appear routine.
Attackers reportedly used this familiarity to create believable phishing messages. A fake voicemail notification can be especially effective because recipients may expect to receive one and may feel pressure to review it quickly.
The campaign demonstrates that attackers do not always need to compromise a trusted platform directly. Sometimes they only need to exploit the trust that users and security systems already place in the platform.
The Safe-Sender Claim Added Psychological Pressure
The phishing emails reportedly displayed a fraudulent message claiming that the sender had been verified through the organization’s safe-sender list.
This tactic targeted human trust rather than only technical controls. A user who sees a verification message may assume that the organization’s security team has already approved the sender.
The danger is that technical security labels can become social-engineering tools when attackers imitate them. Users may lower their guard precisely because the message appears to contain evidence that it has already been checked.
Email Allowlisting May Have Helped the Attack Bypass Defenses
Trust Rules Can Override Important Warning Signals
According to the researchers, the malicious emails failed SPF and DMARC checks and did not contain a valid DKIM signature. Under normal circumstances, these signals could contribute to a message being treated as suspicious.
However, if an organization creates broad allowlisting rules for a trusted domain, those rules may override or weaken other security checks.
This creates a dangerous situation in which a message can appear trustworthy because of the domain it claims to represent even when the underlying authentication evidence is missing or invalid.
Blanket Exceptions Create Long-Term Risk
Allowlisting is often introduced to solve a practical problem. A legitimate vendor’s messages may be delayed, quarantined, or incorrectly classified as spam. Administrators may then create a broad exception to ensure that future messages are delivered.
Over time, these exceptions can accumulate. A rule created years earlier may remain active even after the vendor changes its email infrastructure or the organization adopts stronger security controls.
Attackers can search for these weak points and deliberately impersonate brands that are likely to receive special treatment.
The SCL -1 Result Shows How Filtering Logic Can Be Manipulated
What a Spam Confidence Level of -1 Means
Microsoft Exchange uses Spam Confidence Level values to help determine how messages should be handled. An SCL value of -1 is generally associated with messages that are treated as trusted or bypass certain spam-filtering actions.
If a malicious email reaches this status because of an overly broad allowlist, the message may avoid the security inspection that would normally identify suspicious characteristics.
The problem is not necessarily the SCL value itself. The deeper issue is the policy or trust decision that allowed the message to receive that treatment.
Security Exceptions Need Continuous Review
Organizations should treat allowlisting as a temporary and narrowly defined exception rather than a permanent trust guarantee.
A safer approach is to require valid authentication while still allowing legitimate vendor traffic. For example, a rule can verify that messages originate from approved infrastructure and pass authentication checks instead of trusting every message that merely uses a familiar domain.
Token Replay Can Turn a Phishing Click Into Long-Term Account Access
Stolen Tokens May Outlive the Original Login
After the phishing stage, attackers reportedly replayed Microsoft 365 authentication tokens using VPS and commercial VPN services.
A token can act as proof that an authentication process has already occurred. If an attacker obtains a usable token, the attacker may be able to access cloud resources without entering the victim’s password again.
This is one reason modern incident response must go beyond changing passwords. Password resets may not immediately invalidate every active session or refresh token.
Persistent Access Creates More Opportunities
Researchers observed access lasting for more than two weeks in some cases. That amount of time can allow attackers to study an organization, identify valuable users, search for financial information, and prepare additional attacks.
Long-term access also increases the risk of internal phishing. Attackers can send messages from a legitimate account, making them more believable to coworkers and business partners.
Microsoft Graph Can Expand the Scope of a Compromise
One Account Can Reveal an Entire Business Environment
Microsoft Graph provides a unified interface for accessing Microsoft 365 services. Depending on the permissions available, it can expose a wide range of organizational information.
The reported activity included attempts to enumerate Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications.
This means that a compromised identity may become a gateway into the organization’s broader cloud environment.
OAuth Permissions Require Careful Review
Attackers may attempt to create or abuse application permissions that continue providing access even after the original phishing session is disrupted.
Security teams should review newly granted OAuth permissions, unusual application registrations, and consent events that do not match normal business activity.
Administrators should pay particular attention to applications requesting broad access to email, files, user profiles, or organizational data.
The RingCentral Breach Raises Questions About Target Selection
The Timing May Be Relevant
RingCentral recently disclosed a security incident affecting data belonging to a limited portion of its customers. The incident was reportedly claimed by the threat actor known as ShinyHunters.
ZeroBEC suggested that criminals using Greatness may have obtained a list of valid RingCentral users through that incident, potentially helping them identify realistic phishing targets.
However, researchers could not confidently establish a direct connection.
Correlation Is Not Proof
The possibility is important because targeted phishing campaigns become more effective when attackers know which services a victim actually uses.
A generic RingCentral phishing email may fail when sent to someone who has never used the platform. A message sent to a confirmed customer is much more believable.
Still, the available information does not prove that the campaign’s target data came from the RingCentral incident. Security analysis must distinguish between a plausible hypothesis and a verified attribution.
Deep Analysis: How Security Teams Should Hunt for Greatness Activity
Investigate Suspicious Microsoft 365 Sign-Ins
Security teams should review authentication logs for successful sign-ins originating from hosting providers, VPS networks, anonymization services, or unusual commercial VPN locations.
Example Microsoft Sentinel Kusto Query Language:
SigninLogs
| where ResultType == 0
| where IPAddress !startswith 10.
| where AppDisplayName contains Office
| project TimeGenerated, UserPrincipalName, IPAddress,
LocationDetails, AppDisplayName, ClientAppUsed
| order by TimeGenerated desc
This query should be adapted to the organization’s environment. A hosting-provider IP address is not automatically malicious, but it may be suspicious when combined with unusual login behavior.
Search for Impossible Travel and Unusual Locations
SigninLogs
| where ResultType == 0
| summarize Locations = make_set(LocationDetails.countryOrRegion),
IPs = make_set(IPAddress) by UserPrincipalName, bin(TimeGenerated, 24h) | where array_length(Locations) > 2
Multiple countries in a short period may indicate token replay, VPN use, or a compromised account. Analysts should compare the results with known travel and approved remote-access services.
Review OAuth Consent and Application Activity
AuditLogs
| where OperationName has_any (
Consent to application,
Add service principal,
Add app role assignment
)
| project TimeGenerated, InitiatedBy, TargetResources,
OperationName, Result
| order by TimeGenerated desc
Unexpected consent events may reveal persistence mechanisms or unauthorized access to Microsoft Graph resources.
Search for Suspicious Mailbox Activity
OfficeActivity
| where OfficeWorkload == Exchange
| where Operation in (
MailItemsAccessed,
MailboxLogin,
Set-Mailbox,
New-InboxRule
)
| project TimeGenerated, UserId, Operation,
ClientIP, Parameters
| order by TimeGenerated desc
Large volumes of mailbox access, unfamiliar IP addresses, or new forwarding rules should be investigated.
Check for Malicious Inbox Rules
Attackers may create rules that forward messages externally, hide security alerts, or delete evidence.
Example Exchange Online PowerShell command:
Get-InboxRule -Mailbox [email protected] | Select Name, Enabled, Priority, Description
Security teams should review unexpected forwarding destinations and rules created around the suspected compromise period.
Revoke Sessions During Incident Response
If compromise is confirmed or strongly suspected, administrators should revoke active sessions and refresh tokens according to their organization’s Microsoft Entra ID procedures.
Example Microsoft Graph PowerShell command:
Revoke-MgUserSignInSession -UserId [email protected]
This should be combined with password resets where appropriate, MFA review, OAuth-permission analysis, and investigation of all affected Microsoft 365 services.
Audit Safe-Sender and Allowlist Policies
Security teams should identify rules that bypass filtering based only on sender domains.
Example Exchange Online PowerShell:
Get-HostedContentFilterPolicy | Format-List Name,AllowedSenders,AllowedSenderDomains
Broad domain exclusions should be replaced with narrowly scoped rules that still require valid SPF, DKIM, and DMARC authentication.
What Undercode Say:
Trust Has Become a High-Value Attack Surface
The Greatness campaign demonstrates that cybercriminals are no longer attacking only passwords.
They are attacking the trust relationships surrounding identities.
They target trusted brands.
They target safe-sender lists.
They target authentication workflows.
They target the confidence users place in security labels.
The most concerning part is that several layers can fail at once.
A familiar brand makes the email believable.
An allowlist helps the message reach the inbox.
A fake verification banner reduces user suspicion.
An AiTM page captures an authenticated session.
A stolen token provides access after MFA approval.
Microsoft Graph expands the attacker’s visibility.
This is not a single vulnerability.
It is a chain of trust failures.
Organizations often focus on whether an email is malicious.
They should also ask why the email was trusted.
A trusted domain is not the same as a trusted message.
A recognized brand is not proof of a legitimate sender.
An allowlist should never become a permanent bypass.
Security teams should audit every exception.
They should identify rules created to solve old delivery problems.
They should determine whether those rules still serve a valid purpose.
They should require authentication evidence.
They should monitor token usage after successful MFA events.
They should investigate sessions originating from hosting infrastructure.
They should review OAuth permissions continuously.
They should treat cloud identity as a critical security boundary.
The shift toward token theft changes incident response.
Changing a password may not be enough.
Active sessions must be reviewed and revoked.
Refresh tokens may need to be invalidated.
Unauthorized applications must be removed.
Mailbox rules must be inspected.
Microsoft Graph activity must be examined.
Organizations should also reduce dependence on user judgment.
Employees cannot be expected to detect every advanced phishing flow.
Security architecture must prevent dangerous actions.
Phishing-resistant authentication should become a priority.
Conditional access policies should evaluate device, location, risk, and session context.
The Greatness platform may continue to evolve.
Its operators will likely add new brands and authentication methods.
Defenders must therefore focus on behaviors rather than only indicators.
The goal is not simply to block one phishing domain.
The goal is to break the entire attack chain.
✅ Greatness Has Expanded Beyond Basic Credential Phishing
The report describes Greatness as an evolving phishing-as-a-service platform that supports AiTM and device-code phishing techniques. This is consistent with the broader trend of phishing kits targeting authentication sessions rather than only passwords.
The platform has reportedly expanded its targeting beyond Microsoft 365 to include services such as iCloud, Yahoo, and Google Workspace.
The reported subscription model also reflects the growing commercialization of cybercrime tools.
✅ Allowlisting Can Create Security Blind Spots
Broad safe-sender rules can cause messages to receive less scrutiny than ordinary email.
If an allowlist trusts a domain without requiring valid authentication, attackers may exploit the exception by impersonating that domain.
Organizations should review allowlists regularly and avoid permanent blanket exclusions.
✅ AiTM Attacks Can Undermine Traditional MFA
AiTM phishing can capture session information after a user completes a legitimate MFA challenge.
This does not mean MFA is ineffective; it means that some MFA methods are more resistant to phishing than others.
Passkeys and hardware-backed authentication can reduce exposure to many credential-relay attacks.
⚠️ The Connection to the RingCentral Data Incident Is Not Confirmed
Researchers suggested that valid RingCentral customer information may have helped attackers identify targets.
However, the available evidence does not establish that Greatness operators obtained target lists from the RingCentral incident.
The possible relationship should therefore be treated as a hypothesis rather than a confirmed attribution.
Prediction
(+1) Identity Security Will Become More Context-Aware
Over the next year, more organizations are likely to strengthen identity defenses by combining phishing-resistant authentication, conditional access, device trust, session monitoring, and token-risk analysis.
Security platforms will increasingly evaluate what happens after MFA approval rather than treating successful MFA as the end of the authentication process.
This should improve the detection of token replay and suspicious cloud activity.
(-1) Phishing Services Will Continue to Automate Advanced Attacks
PhaaS platforms are likely to add more automated templates, brand impersonation options, and authentication-bypass techniques.
Criminals may increasingly use AI-assisted content to create more convincing messages tailored to specific industries and organizations.
The result could be a higher volume of phishing campaigns that appear professionally written and technically credible.
(+1) Broad Email Allowlisting Will Decline
Organizations are likely to replace simple domain-based trust rules with authentication-aware policies.
Security teams will place greater emphasis on SPF, DKIM, DMARC alignment, message provenance, and behavioral analysis.
This shift could reduce the effectiveness of attacks that exploit trusted vendor names.
(-1) Stolen Cloud Sessions Will Become More Valuable
As password protections improve, attackers may place greater emphasis on stealing active sessions, refresh tokens, OAuth permissions, and application access.
Cloud identity will remain one of the most attractive targets because a single compromised account can expose multiple services.
Defenders will need to treat session security as seriously as password security.
Final Perspective: The Next Phishing Battle Is About Trust
The Greatness campaign shows that modern phishing is becoming an attack on the systems people rely on to establish legitimacy.
The attacker does not always need a software vulnerability.
Sometimes an outdated allowlist is enough.
Sometimes a trusted brand is enough.
Sometimes one approved MFA request is enough.
The strongest defense is a layered strategy that verifies email authenticity, limits trust exceptions, uses phishing-resistant authentication, monitors cloud sessions, and responds quickly when suspicious access appears.
In the modern cloud environment, trust must be continuously verified—not granted permanently.
▶️ Related Video (80% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




