Actor Profile
Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers. The platform initially focused on credential phishing targeting Microsoft 365 users but has evolved to support multiple platforms including iCloud, Yahoo, and Google Workspace. Greatness operators provide turnkey phishing infrastructure to customers, enabling lower-skilled threat actors to conduct sophisticated attacks against enterprise cloud services. The service has primarily targeted victims in the United States, Canada, the UK, Australia, and South Africa, with a focus on technology and enterprise sectors.
TTPs (Tactics, Techniques, Procedures)
Initial access via email phishing (T1566.002) spoofing RingCentral communications, leveraging whitelisted domains to achieve SCL -1 on Microsoft Exchange and bypass email security filters. Adversary-in-the-middle (AiTM) attacks (T1557) capture MFA-approved authentication tokens, supplemented by device-code phishing flows. Post-compromise, operators replay stolen Microsoft 365 tokens from VPS and commercial VPN infrastructure (T1078.004) to maintain valid accounts access. Discovery activities (T1087, T1083) include enumeration of Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications via Microsoft Graph API queries. Persistence maintained for over two weeks in observed cases, with access from hosting and VPN addresses indicating operational security measures.
Targets & Patterns
Greatness primarily targets Microsoft 365 users in technology and enterprise sectors across English-speaking countries (US, Canada, UK, Australia, South Africa). Recent campaigns specifically targeted actual RingCentral users, likely leveraging victim lists obtained from the July 2024 RingCentral data breach claimed by ShinyHunters, though this connection remains unconfirmed. The platform's expansion to support iCloud, Yahoo, and Google Workspace indicates broadening target scope beyond Microsoft ecosystems. Targeting patterns suggest focus on organizations with business communication platforms and cloud-based collaboration tools, where compromised accounts provide access to sensitive corporate communications, file repositories, and business intelligence across multiple Microsoft 365 services.
Historical Context
Greatness has been active since mid-2022, initially focusing on credential phishing against Microsoft 365 accounts. The platform has evolved significantly over its operational lifespan, expanding from basic credential harvesting to sophisticated adversary-in-the-middle attacks capable of bypassing MFA protections. The recent campaign represents a tactical evolution incorporating device-code phishing flows alongside AiTM techniques. The platform's commercialization model via Telegram channels follows established PhaaS trends seen in other platforms like Bluekit and Forg365. The suspected use of RingCentral breach data from July 2024 demonstrates opportunistic exploitation of third-party compromises to enhance targeting accuracy and social engineering effectiveness.
Defensive Recommendations
- Audit safe-sender lists and replace blanket domain exclusions with rules requiring valid SPF, DKIM, and DMARC authentication; remove overly permissive whitelisting of third-party communication platforms
- Hunt for suspicious MFA-approved Microsoft 365 sign-ins (T1078.004) originating from hosting providers, VPS infrastructure, or commercial VPN addresses using Entra ID sign-in logs
- Monitor Microsoft Graph API enumeration activity (T1087, T1083) for unusual bulk queries against mailboxes, SharePoint, OneDrive, Teams, and application registrations within short timeframes
- Implement Conditional Access policies requiring compliant devices and blocking sign-ins from anonymizing services; enable continuous access evaluation (CAE) to reduce token lifetime exposure
- Upon suspected compromise, immediately revoke all access and refresh tokens, review OAuth consent grants for suspicious applications, audit Microsoft Graph activity logs, and reset credentials for affected accounts
