Greatness Expands Microsoft 365 Phishing with AiTM and Device Code Attacks
The phishing-as-a-service platform Greatness , active since at least mid-2022, has expanded its campaigns targeting Microsoft 365 users. The activity
Illustrative image generated with AI
Campaign Abuses RingCentral to Bypass Filters
The phishing-as-a-service platform Greatness, active since at least mid-2022, has expanded its campaigns targeting Microsoft 365 users. The activity combines adversary-in-the-middle (AiTM) phishing, device code phishing, and techniques designed to maintain access to cloud accounts.
A campaign analyzed by ZeroBEC exploited the reputation of RingCentral, using seemingly legitimate senders and domains to improve message deliverability. The lures impersonated voicemail notifications and performance review communications.
Recipients were directed to fake Microsoft 365 pages. The campaign targeted organizations in the United States, Canada, the United Kingdom, Australia, and South Africa.
Greatness is marketed through Telegram for $289 per month.
Bypassing Email Whitelists and Security Controls
The messages analyzed failed SPF and DMARC checks and lacked a valid DKIM signature. Nevertheless, some were accepted because corporate configurations treated RingCentral as a trusted sender or domain.
In several cases, Exchange assigned the emails an SCL -1 value, indicating that they were excluded from standard spam filtering. Abuse of safe-sender lists therefore allowed the lures to reach users’ inboxes.
The issue is not limited to the message’s apparent authenticity. An overly broad whitelist can neutralize controls that would normally flag the anomaly.
Token Theft and Access to Cloud Services
In AiTM phishing attacks, the victim approves multifactor authentication on a page controlled by the attackers. Greatness can then steal session tokens and reuse them without necessarily knowing the password.
The second technique uses device codes to trick users into authorizing attacker-controlled access. The acquired tokens are subsequently reused from VPS infrastructure and commercial VPN services.
Access can extend to Outlook, Teams, SharePoint, OneDrive, Exchange, and Microsoft Graph. Attackers can therefore access email, conversations, files, contacts, calendars, and data stored in Microsoft 365 services.
In some cases, persistence lasted for more than two weeks. The risk is significant because the compromise may continue even after the password is changed.
A possible connection to the RingCentral incident disclosed on July 28 has not been confirmed.
Security Controls and Incident Response
Organizations should review sender and domain allowlists, reducing broad exclusions. Where possible, exceptions should be replaced with mandatory SPF, DKIM, and DMARC verification.
Security teams can look for:
- Microsoft 365 sign-ins approved through MFA from VPS, hosting, or VPN infrastructure;
- unusual activity involving Microsoft Graph;
- unauthorized registered applications and OAuth consents;
- suspicious mailbox rules;
- indicators and infrastructure associated with Greatness.
In the event of a compromise, organizations should revoke sessions and tokens, force token renewal, and review access to Exchange, Outlook, Teams, SharePoint, and OneDrive. The investigation should also cover mailboxes, registered applications, OAuth consents, and anomalous account activity.
Sources
This article is an original reworking based on the sources below.




