Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Home/CyberSecurity News/Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
CyberSecurity News

Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts

Key Takeaways Greatness, a new Phishing-as-a-Service (PhaaS) platform, is actively targeting Microsoft 365 users. It bypasses traditional email security protocols like SPF, DKIM, and DMARC, often due...

Sarah simpson
Sarah simpson
August 5, 2026 5 Min Read
2 0

Key Takeaways

  • Greatness, a new Phishing-as-a-Service (PhaaS) platform, is actively targeting Microsoft 365 users.
  • It bypasses traditional email security protocols like SPF, DKIM, and DMARC, often due to misconfigured “safe sender” lists.
  • Greatness employs advanced techniques, including Adversary-in-the-Middle (AiTM) phishing and device-code phishing, to steal authentication tokens and circumvent Multi-Factor Authentication (MFA).
  • Compromised accounts grant attackers access to various Microsoft 365 services, enabling further fraud and internal phishing within an organization.
  • Organizations must urgently review email trust rules, monitor for unusual login patterns, and revoke all active tokens in the event of a suspected compromise.

Greatness PhaaS Emerges, Bypassing Microsoft 365 Security and MFA

A sophisticated Phishing-as-a-Service (PhaaS) platform named Greatness has surfaced, designed specifically to compromise Microsoft 365 accounts, even those protected by Multi-Factor Authentication (MFA). Unlike simpler phishing attempts that merely harvest credentials, Greatness is capable of capturing valid sign-in tokens, granting attackers direct access to cloud services as the legitimate user.

Table Of Content

  • Key Takeaways
  • Greatness PhaaS Emerges, Bypassing Microsoft 365 Security and MFA
  • Advanced Attack Vectors Employed
  • What You Should Do

Recent campaigns leveraging Greatness have been observed using highly convincing spoofed emails, impersonating services like RingCentral voicemail and internal performance review notices. These malicious emails successfully reached recipient inboxes despite failing standard email authentication checks, including SPF, DKIM, and DMARC. This bypass was often facilitated by organizational “safe sender” exclusions, inadvertently turning a convenience feature into a critical vulnerability.

Analysts at ZeroBEC uncovered this activity during an investigation into four suspicious emails targeting a protected organization. According to a report shared with Cyber Security News (CSN), the Greatness campaign orchestrates real-time login relays, device-code phishing, and is managed centrally by operators via Telegram.

Advanced Attack Vectors Employed

The implications of a Greatness compromise extend beyond a single hijacked mailbox. A stolen authentication token can grant attackers access to a victim’s Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and any registered applications. This access can then be leveraged for further fraudulent activities or to launch internal phishing campaigns across the entire tenant. This highlights the ongoing threat posed by real-time AiTM phishing attacks, even in environments with robust MFA deployments.

Initially identified as a phishing kit, Greatness has evolved into a full-fledged service. It provides malicious operators with pre-built lures, customizable domains, and tools to target not only Microsoft 365 but also iCloud, Yahoo, and Google Workspace. Researchers have documented instances where operators utilized deceptive voicemail messages and appraisal notifications to entice users into clicking malicious links.

The attack chain typically begins with an impersonation of a trusted brand, followed by multiple redirects, eventually leading the victim to an attacker-controlled page. The platform also incorporates anti-analysis measures, such as checks for automated browsers and human verification steps. This layered approach can hinder automated security scanning and mirrors tactics observed in other advanced MFA bypass campaigns.

At its core, Greatness functions as a live proxy, relaying communication between the victim and the legitimate Microsoft 365 login portal. Victims are presented with an authentic-looking login page, enter their credentials, and complete the MFA prompt as usual. The Greatness proxy intercepts the issued authentication token, eliminating the need for the attacker to directly bypass MFA.

This method of token capture has significant implications for incident response. A simple password reset may not be sufficient to revoke access, as existing authentication tokens and refresh tokens can remain valid. Security teams must therefore revoke all active sessions in Entra ID, scrutinize OAuth application consents, and identify any unfamiliar sign-ins that have successfully passed MFA, echoing guidance provided for SharePoint AiTM incidents.

Greatness also offers an alternative device-code phishing route. This involves presenting users with document-themed pages that prompt them to enter a code and approve a legitimate sign-in request. This secondary method provides operators with flexibility when a live proxy is not feasible. The shared backend infrastructure of Greatness means that while campaign domains may change, core operational patterns often remain consistent.

What You Should Do

  • Audit Email Trust Rules: Immediately review all “safe sender” lists and transport-rule exclusions within your email security configurations, particularly those pertaining to common software vendors. Ensure that domains receive special treatment only if their mail consistently passes expected authentication checks (SPF, DKIM, DMARC).
  • Monitor for Unusual Login Patterns: Actively hunt for suspicious domains, proxy addresses, unexpected Laravel cookies, and rapid access to multiple Microsoft 365 services from new or uncharacteristic network locations.
  • Investigate MFA-Approved Logins: Scrutinize any MFA-approved logins originating from hosting or VPN infrastructure that does not align with a user’s typical location or device.
  • Enhance Detection Capabilities: Implement checks to verify that the sender, claimed brand, and destination domain in emails are consistent. This can help detect sophisticated spoofing attempts.
  • Post-Compromise Response: In the event of a suspected AiTM compromise, promptly revoke all active and refresh tokens, force credential rotations, thoroughly inspect mailbox rules and OAuth consents, and review Microsoft Graph activity for anomalies.
  • Block Known Infrastructure, Monitor Behavior: While blocking known malicious infrastructure is helpful, prioritize behavioral monitoring, as phishing operators can rapidly change domains and proxy nodes.

Indicators of Compromise (IoCs):-Detailed IoCs are available in the ZeroBEC report.

Type Indicator Description
Domain searchbriefing[.]com Initial click-tracking redirect
Domain loading[.]finreportviewersoftware[.]sbs Anti-analysis redirector
Domain api-8g9ezadxs[.]onewayoutlook[.]one Operator API endpoint
Domain onewayoutolook[.]one Greatness phishing domain
Domain xdccoc[.]top AiTM credential-theft domain
Domain nawarra[.]top AiTM phishing domain
Domain saileventpartners[.]top AiTM phishing domain
Domain greatwallwebsite[.]blog Greatness backend panel API
Domain hashmiaghayi[.]cfd Operator-provisioned phishing domain
Domain addtoitinnew[.]sbs Phishing domain exposed in panel
Domain willgrantitinfewsecondafter[.]cfd Phishing domain exposed in panel
Domain lookatemailplease[.]one Phishing domain exposed in panel
Domain pleasebepatienttoload[.]sbs Phishing domain exposed in panel
Domain landfomarkpool[.]nl Device-code phishing landing page
Domain 638uneconomical[.]birchibase[.]co[.]nl Device-code phishing redirector
IP address 212[.]227[.]146[.]181 IONOS email origin used for spoofed sender activity
IP address 38[.]248[.]95[.]214 Common AiTM proxy and post-compromise login infrastructure
IP address 38[.]248[.]95[.]228 Candidate monitoring host with matching infrastructure fingerprint
IP address 38[.]248[.]95[.]236 Candidate monitoring host with matching infrastructure fingerprint
IP address 158[.]173[.]166[.]3 Post-compromise login and token-replay activity
IP address 46[.]173[.]240[.]225 Post-compromise VPN exit node
IP address 46[.]173[.]240[.]21 Post-compromise VPN exit node
IP address 46[.]173[.]240[.]190 Post-compromise VPN exit node
IP address 46[.]173[.]240[.]180 Post-compromise VPN exit node
IP address 46[.]173[.]240[.]127 Post-compromise VPN exit node
IP address 46[.]173[.]240[.]118 Post-compromise VPN exit node
IP address 46[.]173[.]240[.]17 Post-compromise VPN exit node
Email address serviceringcentral[.]com Spoofed sender address
Operator token 8g9ezadxs Campaign token associated with redirector activity
Operator token 4am16l1tm Campaign token tied to nawarra[.]top and saileventpartners[.]top
Cookie name laravelsession Laravel session cookie observed on suspicious infrastructure
Cookie name XSRF-TOKEN Laravel anti-forgery cookie observed on suspicious infrastructure
Web-page title just a momment Misspelled redirector title used as a hunting fingerprint
URL path rgateclus Redirector routing-path pattern
Subdomain pattern api-[9-character-token][.]domain Greatness operator API domain convention
Display name pattern Your target-domain[.]com Performance Check Spoofed email display-name pattern
Subject pattern Action required: Review your performance appraisal Observed urgency-themed phishing subject
Subject pattern URGENT: Your Performance Review is Ready Observed urgency-themed phishing subject
Subject pattern Appraisal Awesomeness: Your Moment of Truth Observed urgency-themed phishing subject

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachphishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year

Next Post

Poison Claude Sells AI Tokens From Fake Accounts and Free Credits

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us