The Greatness phishing-as-a-service (PhaaS) platform has emerged as a significant threat to Microsoft 365 security, effectively bypassing multi-factor authentication (MFA). This platform captures legitimate sign-in tokens, allowing attackers unauthorized access to various cloud services as if they were the legitimate user.
Phishing Tactics and Campaigns
Recent campaigns have exploited fake RingCentral voicemail and performance-review emails to infiltrate inboxes. Despite failing SPF, DKIM, and DMARC checks, these emails bypassed security through domain-based safe-sender exclusions. Analysts at ZeroBEC discovered this activity during an investigation of phishing emails targeting a secured organization.
ZeroBEC’s report, shared with Cyber Security News, highlights the combination of real-time login relays, device-code phishing, and a centralized operator service delivered via Telegram. These tactics not only compromise individual mailboxes but also expose services like Outlook, Teams, and OneDrive, enabling further fraudulent activities.
Evolution of the Greatness Platform
Initially introduced as a phishing kit, Greatness has evolved into a comprehensive service offering pre-configured lures and tools targeting platforms such as Microsoft 365, iCloud, Yahoo, and Google Workspace. Attackers employ lookalike messages urging recipients to engage with purported recordings or appraisal notices.
The attack chain often begins with impersonation of a trusted brand, leading victims through redirects to attacker-controlled pages. This approach includes human verification steps, complicating routine scanning methods, and mimics tactics from recent MFA bypass campaigns.
Security Implications and Recommendations
Greatness’ ability to act as a live relay between victims and Microsoft 365 highlights a critical distinction in incident response. Simply resetting passwords may not be effective, as existing tokens remain valid. Security teams should revoke active sessions, scrutinize OAuth consents, and identify unfamiliar sign-ins that have passed MFA.
The platform also provides a device-code phishing route using document-themed pages. This alternative path is useful when a live proxy is not feasible. Despite infrastructure changes, core operational patterns remain consistent, necessitating vigilant monitoring.
Preventative Measures for Organizations
Organizations must audit safe-sender lists and transport-rule exclusions to prevent email protection failures due to configuration errors. Special treatment of domains should only occur when authentication checks are passed. Breach notices from vendors should prompt reviews of customer lists to mitigate potential spoofing risks.
Security teams can enhance detection by verifying sender, brand, and domain consistency. Investigating rapid access to multiple Microsoft 365 services from new networks and unusual MFA-approved logins can also indicate compromise. After suspected attacks, revoking tokens, rotating credentials, and inspecting mailbox rules are crucial steps.
In conclusion, the Greatness PhaaS platform underlines the need for robust security practices and continuous vigilance to prevent unauthorized access to cloud services, even with MFA in place.
