Greatness is a phishing-as-a-service platform used by financially motivated cybercriminals to conduct credential phishing, adversary-in-the-middle phishing, and device-code phishing, primarily against Microsoft 365 accounts. Active since at least mid-2022, it has been described as a highly capable phishing service that lowers the barrier to entry for affiliates by providing standardized tooling, deployment workflows, and support. Greatness is designed to help operators bypass common account protections, including multi-factor authentication in some attack flows. Its capabilities include realistic Microsoft 365-themed phishing pages, pre-population of victim email addresses, dynamic branding that mirrors a target organization’s legitimate login experience, IP filtering, and integration with Telegram for operational notifications. It also supports proxy-based adversary-in-the-middle workflows that can capture MFA-approved authentication tokens or session material for later replay. Observed Greatness-enabled campaigns have used spoofed enterprise communications themes to lure legitimate business users into phishing flows. In one documented pattern, victims were redirected into either an adversary-in-the-middle authentication sequence or a device-code phishing sequence targeting Microsoft 365. After successful compromise, operators replayed captured authentication tokens to access cloud accounts and used Microsoft Graph to enumerate mailbox contents, Teams conversations, SharePoint resources, OneDrive files, contacts, calendars, and registered applications. Access to compromised accounts has in some cases persisted for more than two weeks. Greatness has also been reported targeting additional platforms beyond Microsoft 365, including iCloud, Yahoo, and Google Workspace. Microsoft has referenced a related emerging cluster as Storm-1295 in connection with Greatness development activity. Greatness is best understood as a criminal service platform rather than a nation-state actor, with activity centered on scalable phishing, token theft, and post-compromise cloud data access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service operation conducting credential phishing, adversary-in-the-middle phishing, and device-code phishing against Microsoft 365 and other cloud-service users to steal credentials and MFA-approved authentication tokens for account takeover.
Group in development tracked by Microsoft as Storm-1295.
A phishing-as-a-service operation focused on Microsoft 365 phishing that enables affiliates to conduct convincing credential theft campaigns, including MFA bypass and adversary-in-the-middle style theft of credentials or cookies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.