ProBackend
ai cybersecurity deception tactics
1 hour ago4 min read

The Greatness PhaaS Platform's AI Cybersecurity Threats: RingCentral Spoofing and OAuth Device-Code Attacks

How The Greatness phishing-as-a-service platform evolved from credential phishing to sophisticated AiTM and device-code OAuth attacks targeting Microsoft 365, abusing RingCentral to bypass email security filters.

The Greatness PhaaS Platform's AI Cybersecurity Threats

The Evolution of a Phishing-as-a-Service Platform

The Greatness phishing-as-a-service operation didn't just get smarter—it got surgical. What started as basic credential phishing in mid-2022 has matured into a dual-threat operation combining adversary-in-the-middle (AiTM) attacks with device-code OAuth exploitation, specifically aimed at Microsoft 365 users.

Operating through a Telegram channel with thousands of subscribers, Greatness charges $289 per month. That's not pocket change for hobbyist hackers. This is a professionalized criminal enterprise targeting enterprises across the United States, Canada, the UK, Australia, and South Africa.

And now? It's expanded beyond Microsoft 365 to hit iCloud, Yahoo, and Google Workspace. The attack surface keeps growing.

How Greatness Bypasses Email Security Filters

Here's where Greatness gets clever—and where most organizations get caught off guard.

The attackers abuse RingCentral, a legitimate business communications platform used for cloud calling, messaging, and voicemail. They send phishing emails claiming to come from [email protected], targeting actual RingCentral users. The lures? Fake voicemail notifications and performance-review alerts. Nothing sparks more urgency than a "performance review" you didn't ask for.

The technical trick is elegant in its simplicity. The malicious emails originate from unknown IONOS mail servers. They fail SPF and DMARC checks. They carry no DKIM signature. Under normal circumstances, these emails would be rejected outright.

But RingCentral is whitelisted by many organizations.

The emails also include a fraudulent banner claiming the sender was verified by the organization's safe-sender list. That visual cue reduces human suspicion at exactly the point where technical filters should be doing their job.

The result? A Spam Confidence Level (SCL) of -1 on Microsoft Exchange. That's the lowest possible rating, meaning the email bypasses normal filtering stages entirely. It lands in the inbox like it belongs there.

The Two-Pronged Attack: AiTM and Device-Code Phishing

Click the button embedded in the email, and you're routed to Greatness infrastructure. From there, the attack branches into two distinct flows:

Adversary-in-the-Middle (AiTM) phishing captures MFA-approved authentication tokens. The attacker sits between you and Microsoft's servers, intercepting credentials and multi-factor authentication responses in real time. By the time you approve the login, the attacker already has your session token.

Device-code phishing exploits Microsoft's OAuth device authorization flow. You're shown a code to enter at a verification URL, then prompted to sign in on another device. Once you do, the attacker receives an authorization code granting access to your account—without ever touching your actual password.

Both approaches sidestep the security mechanisms they were designed to protect against. That's the whole point.

Post-Compromise: What Happens After the Click

This is where Greatness operators differentiate themselves from the casual phishing crowd. They don't just steal credentials and disappear. They build persistence.

Post-compromise, attackers replay Microsoft 365 authentication tokens from virtual private servers and commercial VPN infrastructure. They then enumerate everything accessible through Microsoft Graph:

  • Outlook mailboxes
  • Teams conversations
  • SharePoint sites
  • OneDrive files
  • Contacts and calendars
  • Registered applications

The access can persist for more than two weeks in some cases. That's not a breach. That's a foothold.

The RingCentral Breach Connection

RingCentral recently disclosed a data breach claimed by threat actor ShinyHunters, affecting a "limited portion of customers." The company published a security bulletin on July 28, stating they're communicating with affected customers directly.

ZeroBEC researchers note it's likely that Greatness operators obtained their target list from that breach—people who actually use RingCentral, making the spoofing more credible. A confident connection can't be made, but the circumstantial evidence points in one direction.

What Security Teams Should Do

The recommendations from ZeroBEC are straightforward but often overlooked in practice:

Audit your safe-sender lists immediately. Blanket domain exclusions are an invitation. Replace them with rules requiring valid email authentication. Just because a domain is "trusted" doesn't mean every email from it is legitimate.

Hunt for Greatness infrastructure. Look for suspicious MFA-approved Microsoft 365 sign-ins originating from hosting providers or commercial VPN addresses. Those are red flags, not false positives.

If compromise is suspected, revoke all access and refresh tokens. Then review OAuth consent decisions, examine Microsoft Graph activity logs, and verify access to Microsoft 365 services. Don't assume that removing a password solves the problem—tokens can keep attackers in your environment long after credentials are changed.

Why This Matters for 2026 Cybersecurity Postures

What makes Greatness particularly dangerous isn't just its technical sophistication. It's the business model. A $289/month subscription with thousands of subscribers generates serious revenue. That incentivizes continuous improvement, feature additions, and customer support for buyers who need help deploying campaigns.

The platform's expansion to multiple email providers—Microsoft 365, iCloud, Yahoo, Google Workspace—means organizations can't treat this as a "Microsoft problem." It's an ai cybersecurity threats challenge that spans every major platform.

Security teams log 54% of successful attacks and alert on just 14% of them. The rest move through environments completely unseen. Greatness exploits exactly that gap: the space between automated detection and human investigation.

The question isn't whether organizations will face attacks like this. It's whether they'll be ready when the next campaign hits.

Sources

  • ConsentFix and ClickFix: How Fake OAuth Prompts Steal Microsoft 365 Tokens in Seconds

the greatness phaas platforms ai cybersecurity threats

More blogs