Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
A captured token can expose Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications, then support further fraud or internal phishing across the tenant.
Post-compromise, the attacker replayed Microsoft 365 authentication tokens from VPS and commercial VPN infrastructure to access the compromised accounts.
Although the messages originated from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, they were still accepted by the receiving systems because RingCentral was whitelisted.
The commercial phishing-as-a-service (PhaaS) toolkit called Greatness, distributed via Telegram that uses token theft with device code and adversary-in-the-middle (AiTM) credential phishing in single operator products, has become a latest crimeware tool for the threat actors.
Clicking the button embedded in those emails took victims to the Greatness infrastructure, where they were routed either through a Microsoft adversary-in-the-middle (AiTM) phishing flow that captured an MFA-approved authentication token or through a device-code phishing flow.
A captured token can expose Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications, then support further fraud or internal phishing across the tenant.
Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure.
Rather than simply collecting a password, it can capture a valid sign-in token that lets an attacker enter cloud services as the victim.
Victims who end up interacting with a booby-trapped link embedded in the phishing email traverse through a five-stage redirect chain that implements anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate, before taking them to the final destination, which can be either an AitM proxy or a device code endpoint.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service platform that targets cloud identities, especially Microsoft 365, by using adversary-in-the-middle real-time login relays and device-code phishing to capture authentication tokens and bypass MFA protections. It provides operators with lures, configurable domains, and a shared backend managed in part through Telegram.
PhaaS 기반 피싱 키트로 추정되며, HTML 리다이렉터와 피싱 랜딩 페이지를 통해 계정 정보를 탈취한다. URL 해시 기반 이메일 자동 추출, 도메인 기반 페이지 동적 개인화, 세션 기반 시도 횟수 추적을 통한 심리적 기만 기능이 언급된다.
A phishing-as-a-service toolkit focused on Microsoft 365 that enables convincing phishing pages, MFA bypass, IP filtering, Telegram bot integration, and man-in-the-middle theft of credentials or session cookies.
Phishing-as-a-Service kit used to target Microsoft 365 users via phishing to capture credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.