Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers.

Rather than simply collecting a password, it can capture a valid sign-in token that lets an attacker enter cloud services as the victim.

A recent campaign used spoofed RingCentral voicemail and performance-review emails to reach inboxes.

The messages failed SPF, DKIM, and DMARC checks, yet domain-based safe-sender exclusions overrode those failures. This turns a convenience setting into an opening for attackers.

Analysts at ZeroBEC identified the activity while investigating four emails sent to a protected organization.

ZeroBEC said in a report shared with Cyber Security News (CSN) that the campaign combined real-time login relays, device-code phishing, and a centrally managed operator service delivered through Telegram.

Phishing email body as rendered in the inbox (Source – ZeroBec)

The impact goes beyond a single stolen mailbox. A captured token can expose Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications, then support further fraud or internal phishing across the tenant. The finding also reinforces why real-time AiTM phishing attacks deserve attention even where MFA is widely deployed.

Greatness PhaaS Bypasses Email Security and MFA

Greatness first appeared as a phishing kit, but it has grown into a service that gives operators ready-made lures, configurable domains, and tools to target Microsoft 365, iCloud, Yahoo, and Google Workspace.

Researchers saw operators use lookalike voicemail messages that urged recipients to open an alleged recording or appraisal notice.

The delivery chain begins with a trusted-brand impersonation and can pass through several redirects before landing on an attacker-controlled page.

GreatnessBot Telegram landing page (Source – ZeroBec)

It also checks for automated browsers and asks visitors to complete a human-verification step.

This layered approach can make routine scanning less useful and mirrors tactics described in recent MFA bypass campaigns.

At the final stage, Greatness acts as a live relay between the victim and Microsoft 365. The victim sees their organization’s authentic branding, enters a password, and completes the normal MFA prompt.

The relay then receives the issued authentication token, so the criminal does not need to defeat MFA directly.

That distinction matters during incident response. A password reset alone may not remove access because existing tokens and refresh tokens can still work.

Investigators should revoke active sessions in Entra ID, review OAuth application consent, and look for unfamiliar sign-ins that have already passed MFA, as SharePoint AiTM incident guidance has similarly stressed.

Greatness also offers a device-code route, using document-themed pages that persuade users to enter a code and approve a real sign-in.

This gives operators a second route when a live proxy is not suitable. The platform’s shared backend means campaign infrastructure may change while core operational patterns remain connected.

Defenders Need to Check Trust Rules

The campaign shows that email protection can fail through configuration, not a broken security product.

Organizations should audit every safe-sender list and transport-rule exclusion, especially for common software vendors. A domain should receive special treatment only when its mail also passes the expected authentication checks.

Vendor breach notices should trigger the same review. A customer list can reveal which companies are likely to trust a vendor domain, enabling convincing spoofing.

O365 Panel login page (Source – ZeroBec)

Teams can improve detection by checking whether the sender, claimed brand, and destination domain match, a pattern also seen when compromised Outlook accounts spread credential-stealing links.

Security teams should hunt for the listed domains, proxy addresses, unexpected Laravel cookies, and rapid access to several Microsoft 365 services from a new network.

They should also investigate MFA-approved logins from hosting or VPN infrastructure that does not match a user’s usual location or device.

After a suspected AiTM compromise, responders should revoke all active and refresh tokens, rotate credentials, inspect mailbox rules and OAuth consents, and review Microsoft Graph activity.

Blocking known infrastructure can help, but monitoring behavior is essential because phishing operators can replace domains and proxy nodes quickly.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain searchbriefing.com Initial click-tracking redirect
Domain loading.finreportviewersoftware.sbs Anti-analysis redirector
Domain api-8g9ezadxs.onewayoutlook.one Operator API endpoint
Domain onewayoutolook.one Greatness phishing domain
Domain xdccoc.top AiTM credential-theft domain
Domain nawarra.top AiTM phishing domain
Domain saileventpartners.top AiTM phishing domain
Domain greatwallwebsite.blog Greatness backend panel API
Domain hashmiaghayi.cfd Operator-provisioned phishing domain
Domain addtoitinnew.sbs Phishing domain exposed in panel
Domain willgrantitinfewsecondafter.cfd Phishing domain exposed in panel
Domain lookatemailplease.one Phishing domain exposed in panel
Domain pleasebepatienttoload.sbs Phishing domain exposed in panel
Domain landfomarkpool.nl Device-code phishing landing page
Domain 638uneconomical.birchibase.co.nl Device-code phishing redirector
IP address 212.227.146.181 IONOS email origin used for spoofed sender activity
IP address 38.248.95.214 Common AiTM proxy and post-compromise login infrastructure
IP address 38.248.95.228 Candidate monitoring host with matching infrastructure fingerprint
IP address 38.248.95.236 Candidate monitoring host with matching infrastructure fingerprint
IP address 158.173.166.3 Post-compromise login and token-replay activity
IP address 46.173.240.225 Post-compromise VPN exit node
IP address 46.173.240.21 Post-compromise VPN exit node
IP address 46.173.240.190 Post-compromise VPN exit node
IP address 46.173.240.180 Post-compromise VPN exit node
IP address 46.173.240.127 Post-compromise VPN exit node
IP address 46.173.240.118 Post-compromise VPN exit node
IP address 46.173.240.17 Post-compromise VPN exit node
Email address serviceringcentral.com Spoofed sender address
Operator token 8g9ezadxs Campaign token associated with redirector activity
Operator token 4am16l1tm Campaign token tied to nawarra.top and saileventpartners.top
Cookie name laravelsession Laravel session cookie observed on suspicious infrastructure
Cookie name XSRF-TOKEN Laravel anti-forgery cookie observed on suspicious infrastructure
Web-page title just a momment Misspelled redirector title used as a hunting fingerprint
URL path rgateclus Redirector routing-path pattern
Subdomain pattern api-[9-character-token].domain Greatness operator API domain convention
Display name pattern Your target-domain.com Performance Check Spoofed email display-name pattern
Subject pattern Action required: Review your performance appraisal Observed urgency-themed phishing subject
Subject pattern URGENT: Your Performance Review is Ready Observed urgency-themed phishing subject
Subject pattern Appraisal Awesomeness: Your Moment of Truth Observed urgency-themed phishing subject

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world