LIVEΒ·
SkylineWire Logo

SkylineWire

Global News & Market Intelligence Β· Verified from Official Dispatches

Editions:
Home
LIVEMARKETS:
S&P 500 5,640.20 (+0.45% β–²)|NASDAQ 17,855.10 (+0.62% β–²)|BRENT CRUDE $82.40 (-0.85% β–Ό)|SAF FUEL $2,140/t (+1.2% β–²)
S&P 500 5,640.20 (+0.45% β–²)|NASDAQ 17,855.10 (+0.62% β–²)|BRENT CRUDE $82.40 (-0.85% β–Ό)|SAF FUEL $2,140/t (+1.2% β–²)
BreakingDeveloping Storyβœ“ Verified Reporting
Cybersecurity· 🌍 Global

Greatness Phishing Service Now Targets Microsoft 365 Accounts

The Greatness phishing-as-a-service platform has updated its toolkit to perform adversary-in-the-middle attacks and steal Microsoft 365 account credentials.

By Skyline Wire Newsroom Β· Published Source: BleepingComputer Β· Verified Reporting

Key Story Metrics & Context

Industry Sector:Cybersecurity
Companies Impacted:Microsoft, RingCentral
Geographic Scale:Global
Reporting Status:βœ“ Multi-Source Verified
Greatness Phishing Service Now Targets Microsoft 365 Accounts

Executive Brief & Verified Analysis

βœ“ OFFICIAL SOURCES REVIEWED

Executive Summary

The Greatness phishing-as-a-service platform has updated its toolkit to perform adversary-in-the-middle attacks and steal Microsoft 365 account credentials.

Why This Matters

Key strategic implication: The Greatness PhaaS platform has expanded its capabilities to include adversary-in-the-middle attacks.

Market Impact

Verified for Microsoft, RingCentral. Primary market adjustment vector.

Source Verification

Cross-referenced across regulatory dispatches, official press releases, and verified wire filings.

Strategic Implications

  • βœ“The Greatness PhaaS platform has expanded its capabilities to include adversary-in-the-middle attacks.
  • βœ“The service specifically targets Microsoft 365 account credentials.
  • βœ“New tactics include device-code phishing and the spoofing of RingCentral portals.

The Greatness phishing-as-a-service (PhaaS) platform has significantly upgraded its operational capabilities to execute adversary-in-the-middle (AitM) attacks and device-code phishing targeting Microsoft 365 accounts, according to BleepingComputer. Originally utilized primarily for standard credential theft, the service now employs sophisticated spoofing techniques, including the imitation of RingCentral portals, to bypass security measures.

Evolving Attack Methods

The platform has moved beyond simple fake login pages. By integrating AitM capabilities, threat actors can now intercept session tokens in real-time, allowing them to bypass multi-factor authentication (MFA) protocols enforced by Microsoft 365. The inclusion of device-code phishing provides an additional vector, tricking users into authenticating malicious devices through legitimate Microsoft login prompts.

Attack ComponentPrimary FunctionTarget Platform
Credential PhishingHarvesting User/PassMicrosoft 365
AitM ProxyingSession Token TheftMicrosoft 365
Device-Code FlowMFA BypassMicrosoft 365
Portal SpoofingIdentity DeceptionRingCentral

These tactics represent a shift in the service's maturity, providing non-technical attackers with advanced tools previously reserved for specialized criminal organizations. The automation inherent in the Greatness platform allows these campaigns to scale rapidly, creating a higher volume of targeted lures directed at enterprise environments.

Why It Matters

The expansion of the Greatness platform signifies the commoditization of high-complexity cyberattacks. As PhaaS providers lower the barrier to entry for credential interception, traditional reliance on basic MFA becomes insufficient. This trend shifts the defensive burden from user vigilance to identity provider security. Organizations must now adopt hardware-backed security keys or phishing-resistant authentication methods, as software-based tokens are increasingly vulnerable to these proxy-based interception methods. The persistence of these automated threats suggests that identity-based attacks will remain the primary method for initial corporate network penetration throughout the fiscal year.

Regulatory and Security Context

While Microsoft continues to update its security posture, platforms like Greatness exploit the "human-in-the-loop" phase of authentication. Security researchers consistently track these developments as they mirror broader shifts in the criminal-to-consumer software market. Organizations are encouraged to monitor sign-in logs for anomalous device-code requests.

Expected Next Steps

  • 1Organizations to audit Microsoft 365 logs for unusual device-code authentication attempts.
  • 2Implementation of phishing-resistant hardware security keys for enterprise users.
  • 3Increased monitoring of third-party portal integrations by security operations teams.

Frequently Asked Questions

Greatness is a phishing-as-a-service provider that supplies criminals with tools to conduct automated credential theft campaigns.

It uses adversary-in-the-middle (AitM) techniques to intercept session tokens during the login process, allowing attackers to hijack active sessions.

The platform has been observed spoofing RingCentral portals to deceive users into providing Microsoft 365 credentials.

Source Transparency & Verified Dispatches

βœ“ Verified Primary Data
βœ“
BleepingComputerπŸ’Ό Corporate Dispatch
Source β†—
βœ“
MicrosoftπŸ’Ό Corporate Dispatch
Source β†—

Reader Discussion & Insights

Leave a Comment

Loading discussion thread...

Get Breaking Global Intel in Your Inbox

Subscribe to the Skyline Wire AI Daily Briefing. Direct insights across Aviation, Tech, EVs, and Markets.

Original announcement link: BleepingComputer

phishingcybersecuritymicrosoft365infosecphaas
greatness phishing servicemicrosoft 365 phishingadversary in the middle attackphishing as a servicecredential theftdevice code phishing