Evolution of the Greatness PhaaS Platform

Security researchers at ZeroBEC have identified a concerning advancement in the capabilities of the "Greatness" phishing-as-a-service (PhaaS) platform. Initially designed for basic credential harvesting, the tool has expanded its scope to intercept multi-factor authentication (MFA) tokens. Beyond Microsoft 365, the service now targets accounts across Google Workspace, iCloud, and Yahoo, signaling a broader threat to enterprise and individual security.


Exploiting Brand Trust Through Spoofing

The current campaign leverages the reputation of RingCentral to deceive victims. Following a known data breach involving the ShinyHunters group, threat actors appear to be utilizing exfiltrated customer email lists to distribute highly convincing fraudulent messages. These emails typically mimic standard voicemail notifications or performance reviews.

Although the emails originate from unauthorized servers and fail standard security protocols like SPF and DMARC, they successfully lure users to malicious landing pages. These sites are meticulously crafted to mirror legitimate Microsoft 365 login portals, allowing attackers to perform "Adversary-in-the-Middle" attacks that capture session tokens, effectively rendering MFA protections useless.


Potential Impact and Accessibility

Once attackers gain unauthorized access to a Microsoft 365 account, they gain broad permissions to exploit the victim's environment. According to ZeroBEC, the intruders can navigate through:

  • Outlook mailboxes and Teams communication history
  • OneDrive repositories containing sensitive documents
  • Contacts, calendars, and organizational apps via Microsoft Graph

The Greatness platform is currently marketed on Telegram for $289 per month, a relatively low barrier to entry that has fueled its growth. With a history of activity spanning over four years, the service is primarily focused on regions including the United States, the United Kingdom, Australia, Canada, and South Africa. While the exact scope of the current victim count remains undetermined, the ease of access provided by this "service" poses a significant risk to organizations worldwide.