Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers.
Rather than simply collecting a password, it can capture a valid sign-in token that lets an attacker enter cloud services as the victim.
A recent campaign used spoofed RingCentral voicemail and performance-review emails to reach inboxes.
The messages failed SPF, DKIM, and DMARC checks, yet domain-based safe-sender exclusions overrode those failures. This turns a convenience setting into an opening for attackers.
Analysts at ZeroBEC identified the activity while investigating four emails sent to a protected organization.
ZeroBEC said in a report shared with Cyber Security News (CSN) that the campaign combined real-time login relays, device-code phishing, and a centrally managed operator service delivered through Telegram.
The impact goes beyond a single stolen mailbox. A captured token can expose Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications, then support further fraud or internal phishing across the tenant. The finding also reinforces why real-time AiTM phishing attacks deserve attention even where MFA is widely deployed.
Greatness first appeared as a phishing kit, but it has grown into a service that gives operators ready-made lures, configurable domains, and tools to target Microsoft 365, iCloud, Yahoo, and Google Workspace.
Researchers saw operators use lookalike voicemail messages that urged recipients to open an alleged recording or appraisal notice.
The delivery chain begins with a trusted-brand impersonation and can pass through several redirects before landing on an attacker-controlled page.
It also checks for automated browsers and asks visitors to complete a human-verification step.
This layered approach can make routine scanning less useful and mirrors tactics described in recent MFA bypass campaigns.
At the final stage, Greatness acts as a live relay between the victim and Microsoft 365. The victim sees their organization’s authentic branding, enters a password, and completes the normal MFA prompt.
The relay then receives the issued authentication token, so the criminal does not need to defeat MFA directly.
That distinction matters during incident response. A password reset alone may not remove access because existing tokens and refresh tokens can still work.
Investigators should revoke active sessions in Entra ID, review OAuth application consent, and look for unfamiliar sign-ins that have already passed MFA, as SharePoint AiTM incident guidance has similarly stressed.
Greatness also offers a device-code route, using document-themed pages that persuade users to enter a code and approve a real sign-in.
This gives operators a second route when a live proxy is not suitable. The platform’s shared backend means campaign infrastructure may change while core operational patterns remain connected.
The campaign shows that email protection can fail through configuration, not a broken security product.
Organizations should audit every safe-sender list and transport-rule exclusion, especially for common software vendors. A domain should receive special treatment only when its mail also passes the expected authentication checks.
Vendor breach notices should trigger the same review. A customer list can reveal which companies are likely to trust a vendor domain, enabling convincing spoofing.
Teams can improve detection by checking whether the sender, claimed brand, and destination domain match, a pattern also seen when compromised Outlook accounts spread credential-stealing links.
Security teams should hunt for the listed domains, proxy addresses, unexpected Laravel cookies, and rapid access to several Microsoft 365 services from a new network.
They should also investigate MFA-approved logins from hosting or VPN infrastructure that does not match a user’s usual location or device.
After a suspected AiTM compromise, responders should revoke all active and refresh tokens, rotate credentials, inspect mailbox rules and OAuth consents, and review Microsoft Graph activity.
Blocking known infrastructure can help, but monitoring behavior is essential because phishing operators can replace domains and proxy nodes quickly.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | searchbriefing.com | Initial click-tracking redirect |
| Domain | loading.finreportviewersoftware.sbs | Anti-analysis redirector |
| Domain | api-8g9ezadxs.onewayoutlook.one | Operator API endpoint |
| Domain | onewayoutolook.one | Greatness phishing domain |
| Domain | xdccoc.top | AiTM credential-theft domain |
| Domain | nawarra.top | AiTM phishing domain |
| Domain | saileventpartners.top | AiTM phishing domain |
| Domain | greatwallwebsite.blog | Greatness backend panel API |
| Domain | hashmiaghayi.cfd | Operator-provisioned phishing domain |
| Domain | addtoitinnew.sbs | Phishing domain exposed in panel |
| Domain | willgrantitinfewsecondafter.cfd | Phishing domain exposed in panel |
| Domain | lookatemailplease.one | Phishing domain exposed in panel |
| Domain | pleasebepatienttoload.sbs | Phishing domain exposed in panel |
| Domain | landfomarkpool.nl | Device-code phishing landing page |
| Domain | 638uneconomical.birchibase.co.nl | Device-code phishing redirector |
| IP address | 212.227.146.181 | IONOS email origin used for spoofed sender activity |
| IP address | 38.248.95.214 | Common AiTM proxy and post-compromise login infrastructure |
| IP address | 38.248.95.228 | Candidate monitoring host with matching infrastructure fingerprint |
| IP address | 38.248.95.236 | Candidate monitoring host with matching infrastructure fingerprint |
| IP address | 158.173.166.3 | Post-compromise login and token-replay activity |
| IP address | 46.173.240.225 | Post-compromise VPN exit node |
| IP address | 46.173.240.21 | Post-compromise VPN exit node |
| IP address | 46.173.240.190 | Post-compromise VPN exit node |
| IP address | 46.173.240.180 | Post-compromise VPN exit node |
| IP address | 46.173.240.127 | Post-compromise VPN exit node |
| IP address | 46.173.240.118 | Post-compromise VPN exit node |
| IP address | 46.173.240.17 | Post-compromise VPN exit node |
| Email address | serviceringcentral.com | Spoofed sender address |
| Operator token | 8g9ezadxs | Campaign token associated with redirector activity |
| Operator token | 4am16l1tm | Campaign token tied to nawarra.top and saileventpartners.top |
| Cookie name | laravelsession | Laravel session cookie observed on suspicious infrastructure |
| Cookie name | XSRF-TOKEN | Laravel anti-forgery cookie observed on suspicious infrastructure |
| Web-page title | just a momment | Misspelled redirector title used as a hunting fingerprint |
| URL path | rgateclus | Redirector routing-path pattern |
| Subdomain pattern | api-[9-character-token].domain | Greatness operator API domain convention |
| Display name pattern | Your target-domain.com Performance Check | Spoofed email display-name pattern |
| Subject pattern | Action required: Review your performance appraisal | Observed urgency-themed phishing subject |
| Subject pattern | URGENT: Your Performance Review is Ready | Observed urgency-themed phishing subject |
| Subject pattern | Appraisal Awesomeness: Your Moment of Truth | Observed urgency-themed phishing subject |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…