Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
Key Takeaways Greatness, a new Phishing-as-a-Service (PhaaS) platform, is actively targeting Microsoft 365 users. It bypasses traditional email security protocols like SPF, DKIM, and DMARC, often due...
Key Takeaways
- Greatness, a new Phishing-as-a-Service (PhaaS) platform, is actively targeting Microsoft 365 users.
- It bypasses traditional email security protocols like SPF, DKIM, and DMARC, often due to misconfigured “safe sender” lists.
- Greatness employs advanced techniques, including Adversary-in-the-Middle (AiTM) phishing and device-code phishing, to steal authentication tokens and circumvent Multi-Factor Authentication (MFA).
- Compromised accounts grant attackers access to various Microsoft 365 services, enabling further fraud and internal phishing within an organization.
- Organizations must urgently review email trust rules, monitor for unusual login patterns, and revoke all active tokens in the event of a suspected compromise.
Greatness PhaaS Emerges, Bypassing Microsoft 365 Security and MFA
A sophisticated Phishing-as-a-Service (PhaaS) platform named Greatness has surfaced, designed specifically to compromise Microsoft 365 accounts, even those protected by Multi-Factor Authentication (MFA). Unlike simpler phishing attempts that merely harvest credentials, Greatness is capable of capturing valid sign-in tokens, granting attackers direct access to cloud services as the legitimate user.
Table Of Content
Recent campaigns leveraging Greatness have been observed using highly convincing spoofed emails, impersonating services like RingCentral voicemail and internal performance review notices. These malicious emails successfully reached recipient inboxes despite failing standard email authentication checks, including SPF, DKIM, and DMARC. This bypass was often facilitated by organizational “safe sender” exclusions, inadvertently turning a convenience feature into a critical vulnerability.
Analysts at ZeroBEC uncovered this activity during an investigation into four suspicious emails targeting a protected organization. According to a report shared with Cyber Security News (CSN), the Greatness campaign orchestrates real-time login relays, device-code phishing, and is managed centrally by operators via Telegram.
Advanced Attack Vectors Employed
The implications of a Greatness compromise extend beyond a single hijacked mailbox. A stolen authentication token can grant attackers access to a victim’s Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and any registered applications. This access can then be leveraged for further fraudulent activities or to launch internal phishing campaigns across the entire tenant. This highlights the ongoing threat posed by real-time AiTM phishing attacks, even in environments with robust MFA deployments.
Initially identified as a phishing kit, Greatness has evolved into a full-fledged service. It provides malicious operators with pre-built lures, customizable domains, and tools to target not only Microsoft 365 but also iCloud, Yahoo, and Google Workspace. Researchers have documented instances where operators utilized deceptive voicemail messages and appraisal notifications to entice users into clicking malicious links.
The attack chain typically begins with an impersonation of a trusted brand, followed by multiple redirects, eventually leading the victim to an attacker-controlled page. The platform also incorporates anti-analysis measures, such as checks for automated browsers and human verification steps. This layered approach can hinder automated security scanning and mirrors tactics observed in other advanced MFA bypass campaigns.
At its core, Greatness functions as a live proxy, relaying communication between the victim and the legitimate Microsoft 365 login portal. Victims are presented with an authentic-looking login page, enter their credentials, and complete the MFA prompt as usual. The Greatness proxy intercepts the issued authentication token, eliminating the need for the attacker to directly bypass MFA.
This method of token capture has significant implications for incident response. A simple password reset may not be sufficient to revoke access, as existing authentication tokens and refresh tokens can remain valid. Security teams must therefore revoke all active sessions in Entra ID, scrutinize OAuth application consents, and identify any unfamiliar sign-ins that have successfully passed MFA, echoing guidance provided for SharePoint AiTM incidents.
Greatness also offers an alternative device-code phishing route. This involves presenting users with document-themed pages that prompt them to enter a code and approve a legitimate sign-in request. This secondary method provides operators with flexibility when a live proxy is not feasible. The shared backend infrastructure of Greatness means that while campaign domains may change, core operational patterns often remain consistent.
What You Should Do
- Audit Email Trust Rules: Immediately review all “safe sender” lists and transport-rule exclusions within your email security configurations, particularly those pertaining to common software vendors. Ensure that domains receive special treatment only if their mail consistently passes expected authentication checks (SPF, DKIM, DMARC).
- Monitor for Unusual Login Patterns: Actively hunt for suspicious domains, proxy addresses, unexpected Laravel cookies, and rapid access to multiple Microsoft 365 services from new or uncharacteristic network locations.
- Investigate MFA-Approved Logins: Scrutinize any MFA-approved logins originating from hosting or VPN infrastructure that does not align with a user’s typical location or device.
- Enhance Detection Capabilities: Implement checks to verify that the sender, claimed brand, and destination domain in emails are consistent. This can help detect sophisticated spoofing attempts.
- Post-Compromise Response: In the event of a suspected AiTM compromise, promptly revoke all active and refresh tokens, force credential rotations, thoroughly inspect mailbox rules and OAuth consents, and review Microsoft Graph activity for anomalies.
- Block Known Infrastructure, Monitor Behavior: While blocking known malicious infrastructure is helpful, prioritize behavioral monitoring, as phishing operators can rapidly change domains and proxy nodes.
Indicators of Compromise (IoCs):-Detailed IoCs are available in the ZeroBEC report.
| Type | Indicator | Description |
|---|---|---|
| Domain | searchbriefing[.]com | Initial click-tracking redirect |
| Domain | loading[.]finreportviewersoftware[.]sbs | Anti-analysis redirector |
| Domain | api-8g9ezadxs[.]onewayoutlook[.]one | Operator API endpoint |
| Domain | onewayoutolook[.]one | Greatness phishing domain |
| Domain | xdccoc[.]top | AiTM credential-theft domain |
| Domain | nawarra[.]top | AiTM phishing domain |
| Domain | saileventpartners[.]top | AiTM phishing domain |
| Domain | greatwallwebsite[.]blog | Greatness backend panel API |
| Domain | hashmiaghayi[.]cfd | Operator-provisioned phishing domain |
| Domain | addtoitinnew[.]sbs | Phishing domain exposed in panel |
| Domain | willgrantitinfewsecondafter[.]cfd | Phishing domain exposed in panel |
| Domain | lookatemailplease[.]one | Phishing domain exposed in panel |
| Domain | pleasebepatienttoload[.]sbs | Phishing domain exposed in panel |
| Domain | landfomarkpool[.]nl | Device-code phishing landing page |
| Domain | 638uneconomical[.]birchibase[.]co[.]nl | Device-code phishing redirector |
| IP address | 212[.]227[.]146[.]181 | IONOS email origin used for spoofed sender activity |
| IP address | 38[.]248[.]95[.]214 | Common AiTM proxy and post-compromise login infrastructure |
| IP address | 38[.]248[.]95[.]228 | Candidate monitoring host with matching infrastructure fingerprint |
| IP address | 38[.]248[.]95[.]236 | Candidate monitoring host with matching infrastructure fingerprint |
| IP address | 158[.]173[.]166[.]3 | Post-compromise login and token-replay activity |
| IP address | 46[.]173[.]240[.]225 | Post-compromise VPN exit node |
| IP address | 46[.]173[.]240[.]21 | Post-compromise VPN exit node |
| IP address | 46[.]173[.]240[.]190 | Post-compromise VPN exit node |
| IP address | 46[.]173[.]240[.]180 | Post-compromise VPN exit node |
| IP address | 46[.]173[.]240[.]127 | Post-compromise VPN exit node |
| IP address | 46[.]173[.]240[.]118 | Post-compromise VPN exit node |
| IP address | 46[.]173[.]240[.]17 | Post-compromise VPN exit node |
| Email address | serviceringcentral[.]com | Spoofed sender address |
| Operator token | 8g9ezadxs | Campaign token associated with redirector activity |
| Operator token | 4am16l1tm | Campaign token tied to nawarra[.]top and saileventpartners[.]top |
| Cookie name | laravelsession | Laravel session cookie observed on suspicious infrastructure |
| Cookie name | XSRF-TOKEN | Laravel anti-forgery cookie observed on suspicious infrastructure |
| Web-page title | just a momment | Misspelled redirector title used as a hunting fingerprint |
| URL path | rgateclus | Redirector routing-path pattern |
| Subdomain pattern | api-[9-character-token][.]domain | Greatness operator API domain convention |
| Display name pattern | Your target-domain[.]com Performance Check | Spoofed email display-name pattern |
| Subject pattern | Action required: Review your performance appraisal | Observed urgency-themed phishing subject |
| Subject pattern | URGENT: Your Performance Review is Ready | Observed urgency-themed phishing subject |
| Subject pattern | Appraisal Awesomeness: Your Moment of Truth | Observed urgency-themed phishing subject |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.