Greatness PhaaS Spoofs RingCentral to Bypass Microsoft 365 MFA
The phishing-as-a-service platform now uses AiTM and device-code attacks to steal session tokens from corporate accounts.
The Greatness phishing-as-a-service (PhaaS) platform has updated its attack vectors to target Microsoft 365 accounts by spoofing the RingCentral brand. This evolution marks a shift from simple credential theft to sophisticated techniques designed to neutralize multi-factor authentication (MFA).
According to reports from BleepingComputer and The Hacker News, the platform now utilizes adversary-in-the-middle (AiTM) and device-code phishing to steal session tokens. Attackers lure victims using RingCentral-themed lures, specifically focusing on voicemail notifications, to trick users into providing their Microsoft 365 credentials. By intercepting the authentication process in real-time, the service can bypass traditional MFA protections that previously guarded these corporate accounts.
The Rise of PhaaS
Phishing-as-a-Service lowers the technical barrier for cybercriminals by providing scalable, subscription-based toolkits that automate the deployment of fraudulent campaigns. Greatness was first publicly documented by Cisco Talos in May 2023, though evidence suggests the group has been active in targeting Microsoft 365 business users since at least mid-2022. The platform primarily focuses its efforts on companies located in the U.S., UK, Australia, South Africa, and Canada.
Why MFA Bypass Matters
The transition toward AiTM and device-code phishing represents a critical escalation in the threat landscape. Traditional MFA, while effective against basic password theft, is insufficient against these methods. Device-code phishing is particularly dangerous because it directs users to the actual Microsoft login page, meaning there is no fake site for security software to block. As The Hacker News noted, this approach is "cleaner for the attacker" because the victim interacts with a legitimate domain while the attacker captures the resulting token.
By spoofing a trusted communications brand like RingCentral, attackers exploit professional trust to gain high-level access to corporate environments. Once a session token is stolen, an attacker can maintain access to a user's email and cloud files without needing to re-authenticate, potentially leading to massive data breaches across an organization.
What to Watch
Security teams should monitor for unusual device registration requests and unexpected session token activity within Microsoft 365 environments. As PhaaS platforms like Greatness continue to refine their ability to mimic trusted brands and bypass hardware-level security, the industry must shift toward more robust authentication methods, such as FIDO2-compliant passkeys, which are more resistant to AiTM interception.