The Greatness phishing-as-a-service platform has expanded from credential theft into a broader Microsoft 365 account-takeover operation by adding device-code phishing alongside adversary-in-the-middle and OAuth abuse techniques. Recent campaigns used RingCentral-themed voicemail and performance-review lures to target cloud identity users, with researchers reporting that the emails abused trusted sender configurations to slip past defenses even when SPF, DKIM, and DMARC checks failed. Victims were redirected to Greatness-controlled infrastructure, where attackers captured MFA-approved authentication tokens instead of just usernames and passwords.
After compromise, operators rapidly replayed stolen tokens from VPS and commercial VPN infrastructure to access Microsoft 365 environments, then used Microsoft Graph API to enumerate mailboxes, Teams chats, SharePoint sites, OneDrive files, contacts, calendars, and registered applications. Researchers also observed device registration activity consistent with attempts to obtain Primary Refresh Token persistence and noted that some malicious access persisted for more than two weeks, with delayed follow-on actions likely intended to evade detection. The reporting highlights a wider shift in phishing kits toward token theft and recommends defenses such as blocking device-code authentication through Conditional Access, enforcing phishing-resistant MFA, and auditing policy exceptions.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
RingCentral published a security bulletin on July 28 disclosing a data breach that affected data for a limited portion of its customers. Later reporting noted ShinyHunters claimed responsibility for the incident.
In November 2025, Greatness operators claimed stolen cookies were protected with one-way hashing and could be accessed only by customers using their Telegram account 2FA code. The claim reflected operational changes in how the service handled stolen session data.
A January 2024 report cited Greatness pricing at $120 per month. Later reporting said the subscription price had increased to $289 per month.
Cisco Talos first publicly documented the Greatness phishing-as-a-service toolkit in May 2023. This established public reporting on the platform and its use against Microsoft 365 users.
Cisco Talos said threat actors used the Greatness phishing-as-a-service kit to target Microsoft 365 business users starting at least in mid-2022. The platform was later described as active across multiple countries and cloud identity ecosystems.
After victims authenticated, attackers replayed harvested Microsoft 365 tokens from VPS, VPN, or dedicated proxy infrastructure to access accounts. They then used Microsoft Graph to enumerate resources including Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications, with some access lasting more than two weeks.
In a recent campaign observed by ZeroBEC, attackers used RingCentral-themed phishing emails, including fake voicemail and performance-review notices, to target legitimate RingCentral users. The messages bypassed some recipient defenses by exploiting safe-sender or trusted-sender configurations despite failing SPF, DKIM, and DMARC checks.
Researchers reported that Greatness expanded beyond credential phishing and adversary-in-the-middle attacks by adding device-code phishing support. The new capability abuses the OAuth 2.0 Device Authorization Grant to bypass MFA and steal tokens.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcezerobec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.