Greatness Phishing Service Adds RingCentral Spoofing and Device-Code Phishing to Target Microsoft 365
According to BleepingComputer, the Greatness phishing-as-a-service (PhaaS) platform has expanded beyond basic credential phishing. Operators are now reportedly spoofing RingCentral communications as a lure and incorporating adversary-in-the-middle (AiTM) techniques and device-code phishing to target Microsoft 365 accounts.
Why It Matters
PhaaS kits lower the barrier to entry for attackers by packaging phishing infrastructure, lure templates, and evasion techniques for resale or rental. The reported shift from static credential harvesting to AiTM and device-code flows is significant because both techniques are designed to defeat standard password-based defenses — AiTM proxies can capture session tokens in real time, and device-code phishing abuses a legitimate Microsoft authentication flow to trick users into authorizing an attacker-controlled session. Organizations relying on Microsoft 365 with only password-based or basic MFA protections may be exposed, since both techniques can undermine traditional multi-factor authentication.
What Defenders Should Watch For
- Unexpected or unsolicited RingCentral-branded emails or notifications requesting sign-in or device authorization, especially those linking to Microsoft 365 login flows.
- Anomalous use of the OAuth device-code authentication flow, particularly for accounts or applications that don't normally use it.
- Session token reuse or logins from unfamiliar IP addresses/geographies immediately following a user's authentication event, which can indicate AiTM token theft.
- Conditional access policies that restrict or closely monitor device-code flow, and user awareness training that flags spoofed vendor-branded MFA/communication prompts.
- Reviewing token lifetimes and enabling continuous access evaluation where available to limit the value of stolen session tokens.
This item is based on a single, developing report and details such as full scope, specific indicators of compromise, and confirmed victim organizations are not yet available. Defenders should treat this as an early signal and monitor for further reporting. Read the original coverage at BleepingComputer.