Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers.
Rather than simply collecting a password, it can capture a valid sign-in token that lets an attacker enter cloud services as the victim.
A recent campaign used spoofed RingCentral voicemail and performance-review emails to reach inboxes.
The messages failed SPF, DKIM, and DMARC checks, yet domain-based safe-sender exclusions overrode those failures. This turns a convenience setting into an opening for attackers.
Analysts at ZeroBEC identified the activity while investigating four emails sent to a protected organization.
ZeroBEC said in a report shared with Cyber Security News (CSN) that the campaign combined real-time login relays, device-code phishing, and a centrally managed operator service delivered through Telegram.
Phishing email body as rendered in the inbox (Source – ZeroBec)
The impact goes beyond a single stolen mailbox. A captured token can expose Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications, then support further fraud or internal phishing across the tenant. The finding also reinforces why real-time AiTM phishing attacks deserve attention even where MFA is widely deployed.
Greatness PhaaS Bypasses Email Security and MFA
Greatness first appeared as a phishing kit, but it has grown into a service that gives operators ready-made lures, configurable domains, and tools to target Microsoft 365, iCloud, Yahoo, and Google Workspace.
Researchers saw operators use lookalike voicemail messages that urged recipients to open an alleged recording or appraisal notice.
The delivery chain begins with a trusted-brand impersonation and can pass through several redirects before landing on an attacker-controlled page.
GreatnessBot Telegram landing page (Source – ZeroBec)
It also checks for automated browsers and asks visitors to complete a human-verification step.
This layered approach can make routine scanning less useful and mirrors tactics described in recent MFA bypass campaigns.
At the final stage, Greatness acts as a live relay between the victim and Microsoft 365. The victim sees their organization’s authentic branding, enters a password, and completes the normal MFA prompt.
The relay then receives the issued authentication token, so the criminal does not need to defeat MFA directly.
That distinction matters during incident response. A password reset alone may not remove access because existing tokens and refresh tokens can still work.
Investigators should revoke active sessions in Entra ID, review OAuth application consent, and look for unfamiliar sign-ins that have already passed MFA, as SharePoint AiTM incident guidance has similarly stressed.
Greatness also offers a device-code route, using document-themed pages that persuade users to enter a code and approve a real sign-in.
This gives operators a second route when a live proxy is not suitable. The platform’s shared backend means campaign infrastructure may change while core operational patterns remain connected.
Defenders Need to Check Trust Rules
The campaign shows that email protection can fail through configuration, not a broken security product.
Organizations should audit every safe-sender list and transport-rule exclusion, especially for common software vendors. A domain should receive special treatment only when its mail also passes the expected authentication checks.
Vendor breach notices should trigger the same review. A customer list can reveal which companies are likely to trust a vendor domain, enabling convincing spoofing.
O365 Panel login page (Source – ZeroBec)
Teams can improve detection by checking whether the sender, claimed brand, and destination domain match, a pattern also seen when compromised Outlook accounts spread credential-stealing links.
Security teams should hunt for the listed domains, proxy addresses, unexpected Laravel cookies, and rapid access to several Microsoft 365 services from a new network.
They should also investigate MFA-approved logins from hosting or VPN infrastructure that does not match a user’s usual location or device.
After a suspected AiTM compromise, responders should revoke all active and refresh tokens, rotate credentials, inspect mailbox rules and OAuth consents, and review Microsoft Graph activity.
Blocking known infrastructure can help, but monitoring behavior is essential because phishing operators can replace domains and proxy nodes quickly.
Indicators of Compromise (IoCs):-
TypeIndicatorDescriptionDomainsearchbriefing.comInitial click-tracking redirectDomainloading.finreportviewersoftware.sbsAnti-analysis redirectorDomainapi-8g9ezadxs.onewayoutlook.oneOperator API endpointDomainonewayoutolook.oneGreatness phishing domainDomainxdccoc.topAiTM credential-theft domainDomainnawarra.topAiTM phishing domainDomainsaileventpartners.topAiTM phishing domainDomaingreatwallwebsite.blogGreatness backend panel APIDomainhashmiaghayi.cfdOperator-provisioned phishing domainDomainaddtoitinnew.sbsPhishing domain exposed in panelDomainwillgrantitinfewsecondafter.cfdPhishing domain exposed in panelDomainlookatemailplease.onePhishing domain exposed in panelDomainpleasebepatienttoload.sbsPhishing domain exposed in panelDomainlandfomarkpool.nlDevice-code phishing landing pageDomain638uneconomical.birchibase.co.nlDevice-code phishing redirectorIP address212.227.146.181IONOS email origin used for spoofed sender activityIP address38.248.95.214Common AiTM proxy and post-compromise login infrastructureIP address38.248.95.228Candidate monitoring host with matching infrastructure fingerprintIP address38.248.95.236Candidate monitoring host with matching infrastructure fingerprintIP address158.173.166.3Post-compromise login and token-replay activityIP address46.173.240.225Post-compromise VPN exit nodeIP address46.173.240.21Post-compromise VPN exit nodeIP address46.173.240.190Post-compromise VPN exit nodeIP address46.173.240.180Post-compromise VPN exit nodeIP address46.173.240.127Post-compromise VPN exit nodeIP address46.173.240.118Post-compromise VPN exit nodeIP address46.173.240.17Post-compromise VPN exit nodeEmail addressserviceringcentral.comSpoofed sender addressOperator token8g9ezadxsCampaign token associated with redirector activityOperator token4am16l1tmCampaign token tied to nawarra.top and saileventpartners.topCookie namelaravelsessionLaravel session cookie observed on suspicious infrastructureCookie nameXSRF-TOKENLaravel anti-forgery cookie observed on suspicious infrastructureWeb-page titlejust a mommentMisspelled redirector title used as a hunting fingerprintURL pathrgateclusRedirector routing-path patternSubdomain patternapi-[9-character-token].domainGreatness operator API domain conventionDisplay name patternYour target-domain.com Performance CheckSpoofed email display-name patternSubject patternAction required: Review your performance appraisalObserved urgency-themed phishing subjectSubject patternURGENT: Your Performance Review is ReadyObserved urgency-themed phishing subjectSubject patternAppraisal Awesomeness: Your Moment of TruthObserved urgency-themed phishing subject
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts appeared first on Cyber Security News.



