Cyber Security News

Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers.

Rather than simply collecting a password, it can capture a valid sign-in token that lets an attacker enter cloud services as the victim.

A recent campaign used spoofed RingCentral voicemail and performance-review emails to reach inboxes.

The messages failed SPF, DKIM, and DMARC checks, yet domain-based safe-sender exclusions overrode those failures. This turns a convenience setting into an opening for attackers.

Analysts at ZeroBEC identified the activity while investigating four emails sent to a protected organization.

ZeroBEC said in a report shared with Cyber Security News (CSN) that the campaign combined real-time login relays, device-code phishing, and a centrally managed operator service delivered through Telegram.

Phishing email body as rendered in the inbox (Source – ZeroBec)

The impact goes beyond a single stolen mailbox. A captured token can expose Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications, then support further fraud or internal phishing across the tenant. The finding also reinforces why real-time AiTM phishing attacks deserve attention even where MFA is widely deployed.

Greatness PhaaS Bypasses Email Security and MFA

Greatness first appeared as a phishing kit, but it has grown into a service that gives operators ready-made lures, configurable domains, and tools to target Microsoft 365, iCloud, Yahoo, and Google Workspace.

Researchers saw operators use lookalike voicemail messages that urged recipients to open an alleged recording or appraisal notice.

The delivery chain begins with a trusted-brand impersonation and can pass through several redirects before landing on an attacker-controlled page.

GreatnessBot Telegram landing page (Source – ZeroBec)

It also checks for automated browsers and asks visitors to complete a human-verification step.

This layered approach can make routine scanning less useful and mirrors tactics described in recent MFA bypass campaigns.

At the final stage, Greatness acts as a live relay between the victim and Microsoft 365. The victim sees their organization’s authentic branding, enters a password, and completes the normal MFA prompt.

The relay then receives the issued authentication token, so the criminal does not need to defeat MFA directly.

That distinction matters during incident response. A password reset alone may not remove access because existing tokens and refresh tokens can still work.

Investigators should revoke active sessions in Entra ID, review OAuth application consent, and look for unfamiliar sign-ins that have already passed MFA, as SharePoint AiTM incident guidance has similarly stressed.

Greatness also offers a device-code route, using document-themed pages that persuade users to enter a code and approve a real sign-in.

This gives operators a second route when a live proxy is not suitable. The platform’s shared backend means campaign infrastructure may change while core operational patterns remain connected.

Defenders Need to Check Trust Rules

The campaign shows that email protection can fail through configuration, not a broken security product.

Organizations should audit every safe-sender list and transport-rule exclusion, especially for common software vendors. A domain should receive special treatment only when its mail also passes the expected authentication checks.

Vendor breach notices should trigger the same review. A customer list can reveal which companies are likely to trust a vendor domain, enabling convincing spoofing.

O365 Panel login page (Source – ZeroBec)

Teams can improve detection by checking whether the sender, claimed brand, and destination domain match, a pattern also seen when compromised Outlook accounts spread credential-stealing links.

Security teams should hunt for the listed domains, proxy addresses, unexpected Laravel cookies, and rapid access to several Microsoft 365 services from a new network.

They should also investigate MFA-approved logins from hosting or VPN infrastructure that does not match a user’s usual location or device.

After a suspected AiTM compromise, responders should revoke all active and refresh tokens, rotate credentials, inspect mailbox rules and OAuth consents, and review Microsoft Graph activity.

Blocking known infrastructure can help, but monitoring behavior is essential because phishing operators can replace domains and proxy nodes quickly.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainsearchbriefing.comInitial click-tracking redirect
Domainloading.finreportviewersoftware.sbsAnti-analysis redirector
Domainapi-8g9ezadxs.onewayoutlook.oneOperator API endpoint
Domainonewayoutolook.oneGreatness phishing domain
Domainxdccoc.topAiTM credential-theft domain
Domainnawarra.topAiTM phishing domain
Domainsaileventpartners.topAiTM phishing domain
Domaingreatwallwebsite.blogGreatness backend panel API
Domainhashmiaghayi.cfdOperator-provisioned phishing domain
Domainaddtoitinnew.sbsPhishing domain exposed in panel
Domainwillgrantitinfewsecondafter.cfdPhishing domain exposed in panel
Domainlookatemailplease.onePhishing domain exposed in panel
Domainpleasebepatienttoload.sbsPhishing domain exposed in panel
Domainlandfomarkpool.nlDevice-code phishing landing page
Domain638uneconomical.birchibase.co.nlDevice-code phishing redirector
IP address212.227.146.181IONOS email origin used for spoofed sender activity
IP address38.248.95.214Common AiTM proxy and post-compromise login infrastructure
IP address38.248.95.228Candidate monitoring host with matching infrastructure fingerprint
IP address38.248.95.236Candidate monitoring host with matching infrastructure fingerprint
IP address158.173.166.3Post-compromise login and token-replay activity
IP address46.173.240.225Post-compromise VPN exit node
IP address46.173.240.21Post-compromise VPN exit node
IP address46.173.240.190Post-compromise VPN exit node
IP address46.173.240.180Post-compromise VPN exit node
IP address46.173.240.127Post-compromise VPN exit node
IP address46.173.240.118Post-compromise VPN exit node
IP address46.173.240.17Post-compromise VPN exit node
Email addressserviceringcentral.comSpoofed sender address
Operator token8g9ezadxsCampaign token associated with redirector activity
Operator token4am16l1tmCampaign token tied to nawarra.top and saileventpartners.top
Cookie namelaravelsessionLaravel session cookie observed on suspicious infrastructure
Cookie nameXSRF-TOKENLaravel anti-forgery cookie observed on suspicious infrastructure
Web-page titlejust a mommentMisspelled redirector title used as a hunting fingerprint
URL pathrgateclusRedirector routing-path pattern
Subdomain patternapi-[9-character-token].domainGreatness operator API domain convention
Display name patternYour target-domain.com Performance CheckSpoofed email display-name pattern
Subject patternAction required: Review your performance appraisalObserved urgency-themed phishing subject
Subject patternURGENT: Your Performance Review is ReadyObserved urgency-themed phishing subject
Subject patternAppraisal Awesomeness: Your Moment of TruthObserved urgency-themed phishing subject

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago