Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
S&P 5007,677.28▲ 3.58%NASDAQ26,151.30▲ 4.71%DOW53,577.40▲ 3.14%GOLD4,674.90▲ 14.74%WTI80.17▼ 2.95%BRENT85.05▼ 3.75%EUR/USD1.1669▲ 2.57%USD/JPY159.11▼ 2.88%DXY99.02▼ 2.45%BTC$78,688▼ 0.54%ETH$2,467▼ 0.34%SOL$97.47▼ 1.52%TOTAL CRYPTO$2.66T▼ 3.31%

Greatness PhaaS Spoofs RingCentral to Bypass MFA on Microsoft 365

Greatness phishing-as-a-service platform uses RingCentral spoofing and adversary-in-the-middle attacks to steal MFA-approved tokens from Microsoft 365 users across five countries.

Partner Surfshark VPN

A subscription-based phishing platform called Greatness is exploiting RingCentral’s trusted sender reputation to bypass enterprise email filters and steal Microsoft 365 authentication tokens, including those approved through multifactor authentication. The campaign, uncovered by email security firm ZeroBEC, shows how phishing-as-a-service operators have adapted to exploit whitelisted domains, turning a routine business communications tool into an attack vector targeting organizations across the United States, Canada, the United Kingdom, Australia, and South Africa. The discovery highlights a growing gap between enterprise email security assumptions and the reality of how sophisticated phishing-as-a-service platforms operate.

What Is the Greatness Platform?

Greatness has been active since mid-2022, offering cybercriminals a ready-made phishing toolkit for approximately $289 per month through a Telegram channel with thousands of subscribers. Initially built as a credential-stealing service focused exclusively on Microsoft 365 accounts, the platform has evolved into a full-fledged phishing-as-a-service operation supporting adversary-in-the-middle and device-code attack flows. Beyond Microsoft 365, Greatness now supports attacks against iCloud, Yahoo, and Google Workspace accounts, reflecting the expanding ambitions of subscription-based phishing operators.

The platform provides affiliates with pre-built phishing pages, email templates, and infrastructure management tools, lowering the technical barrier for carrying out sophisticated attacks. The subscription model means that even attackers with limited expertise can deploy campaigns at scale, while the operators continuously update the platform to counter new security measures as they emerge. This industrialization of phishing has made Greatness one of the more persistent threats in the enterprise credential-theft landscape over the past two years.

Adversary-in-the-Middle and Device-Code Phishing

The platform’s evolution from simple credential phishing to adversary-in-the-middle and device-code attacks represents a fundamental shift in how phishing campaigns defeat multifactor authentication. In an AiTM flow, the attacker positions themselves between the victim and Microsoft’s real sign-in page, acting as a transparent relay. When the user completes their MFA challenge, the attacker captures the session token that the legitimate MFA approval produces, along with the cookies that prove the authentication succeeded.

In a device-code flow, victims are directed to enter a code on Microsoft’s legitimate login endpoint, which the attacker then uses to bind the session to a device they control. Both approaches defeat the assumption that a token approved through a user’s phone is proof of a trusted sign-in. Microsoft has previously warned about the growing use of adversary-in-the-middle techniques, noting that stolen session tokens can be replayed from virtual private servers and commercial VPNs to access accounts without raising immediate alarms.

How RingCentral Becomes the Attack Vector

In a recent campaign, Greatness operators exploited RingCentral to bypass email security filters. The attackers spoofed the service@ringcentral.com sender address and sent malicious emails to legitimate RingCentral customers. Messages appeared as voicemail notifications or employee performance-review alerts. Each email included a fabricated notice claiming the sender had been verified through the organization’s safe-sender list. According to ZeroBEC researchers, the messages were routed through an unknown IONOS mail server, giving attackers full control over the sending infrastructure while impersonating RingCentral’s domain identity.

Email Authentication Bypass

Security Check Result Impact
SPF Failed Email did not originate from authorized servers
DMARC Failed Sender identity could not be verified
DKIM Absent No cryptographic signature present
Spam Confidence Level -1 (SCL) Message bypassed normal spam filtering entirely
Whitelist Status RingCentral whitelisted Sender reputation overrode authentication failures

Despite failing all three standard email authentication checks, the messages were accepted by Microsoft Exchange because RingCentral domains were whitelisted. Microsoft Exchange assigned the messages a Spam Confidence Level of -1, which allowed the emails to evade normal spam filtering entirely. A fraudulent banner claiming the sender had been verified through the organization’s safe-sender list was included in the email body, further reducing suspicion among recipients.

What Happens After the Click

Victims who clicked the malicious button were redirected to infrastructure controlled by Greatness operators. Some victims reached an adversary-in-the-middle phishing page that captured authentication tokens after the user completed an MFA request. Others entered a device-code phishing process, which persuaded them to authorize an attacker-controlled session through Microsoft’s legitimate authentication system. After gaining access, the attackers replayed stolen Microsoft 365 tokens through virtual private servers and commercial VPN services, allowing them to enter compromised accounts without completing another standard sign-in.

ZeroBEC observed persistence lasting over two weeks in some cases, with attackers systematically searching Outlook mailboxes, Teams chats, SharePoint, and OneDrive files for sensitive data. The attackers also searched cloud files and collaboration data, suggesting that the goal was not merely credential theft but broad intelligence gathering across the victim’s digital workspace. This pattern of persistent access followed by data exfiltration is consistent with the tactics of both financially motivated cybercriminals and state-sponsored actors who use PhaaS platforms as initial-access vectors.

Enterprise Implications

The attack reveals a structural weakness in how enterprises manage email trust. When organizations whitelist a service like RingCentral to ensure legitimate notifications are never blocked, they create a blind spot that sophisticated phishing operators can exploit. Attackers need only spoof the sender address of a trusted platform to inherit its reputation, bypassing the authentication controls that enterprises rely on to block malicious messages. The RingCentral connection also raises questions about whether the attackers obtained target lists from a separate RingCentral data breach linked to the ShinyHunters threat actor, though no direct connection between the two incidents has been confirmed.

The Greatness campaign underscores a broader industry challenge: traditional email authentication checks are insufficient against attacks that exploit whitelisted sender reputations. As phishing platforms continue to evolve from credential theft to token interception, the assumption that MFA alone provides adequate protection is increasingly difficult to sustain. Organizations that rely on perimeter-based email security without identity-layer protections remain particularly exposed to this class of attack.

Defending Against AiTM and Token Replay

Experts recommend that organizations move beyond traditional email filtering toward identity-layer protections. Key measures include implementing phishing-resistant authentication methods such as FIDO2 hardware keys, deploying conditional access policies that detect token replay from unfamiliar devices or locations, and auditing whitelisted domains to identify services that could be exploited as attack vectors. Organizations should also consider restricting which services can be whitelisted and implement regular reviews of safe-sender lists.

The platform has also expanded beyond Microsoft 365 to support attacks against iCloud, Yahoo, and Google Workspace accounts, ZeroBEC researchers noted, highlighting the breadth of platforms now targeted by subscription-based phishing services.

Security teams should monitor for suspicious MFA-approved logins originating from hosting providers or commercial VPN services, as these are indicators of token replay. Regular user awareness training remains essential, as the most effective defense against sophisticated phishing is still the ability to recognize red flags such as unexpected voicemail or performance-review notifications demanding immediate action. The Greatness campaign is a reminder that even well-defended organizations remain vulnerable when trusted communication channels are weaponized by attackers.

SourcesZeroBEC; BleepingComputer; Windows Report; Kaseya Week in Breach News August 26 2026; Daily Security Review
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch Kodex Database Allegedly Stolen Via Exposed Admin API Read →