Skip to main content
Emerging ThreatsMalware & Ransomware

Phishing Service Greatness Exploits RingCentral to Target Microsoft 365 Accounts

Office setting with phone and laptop on a table, surrounded by mid-tone decor and daylight.

“This incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly,” RingCentral said in a July 28 security bulletin — a disclosure ZeroBEC researchers say may have provided fodder for a recent phishing campaign that impersonated the same communications provider.

Greatness phishing-as-a-service platform

ZeroBEC's analysis centers on Greatness, a phishing-as-a-service (PhaaS) platform active since at least mid-2022. Researchers report Greatness has expanded beyond simple credential phishing to include adversary-in-the-middle (AiTM) attacks and device-code phishing flows against Microsoft 365 accounts. The platform reportedly targets users in the United States, Canada, the UK, Australia, and South Africa and has evolved to hit multiple account types, including Microsoft 365, iCloud, Yahoo, and Google Workspace. Greatness is advertised for sale at $289 per month to cybercriminal customers on a Telegram channel with thousands of subscribers.

RingCentral spoofing tactic used to bypass filters

In the recent campaign observed by ZeroBEC, Greatness operators spoofed RingCentral by claiming emails originated from service@ringcentral[.]com and using fake voicemail and performance-review notifications as lures. The messages actually came from an unknown IONOS mail server, failed SPF and DMARC checks, and carried no DKIM signature — yet many recipients’ systems accepted them because RingCentral had been whitelisted inside the victim organizations.

ZeroBEC highlights an additional human-layer deception: the emails included a fraudulent banner asserting the sender had been verified by the recipient organization’s safe-sender list. That combined technical and visual leverage produced a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, which effectively allowed the messages to bypass normal filtering stages.

Microsoft 365 AiTM and device-code flows observed

When victims clicked the phishing button, they were routed into Greatness infrastructure and then directed into one of two attack flows identified by ZeroBEC. The first used a Microsoft adversary-in-the-middle (AiTM) phishing flow that captured an MFA-approved authentication token. The second used a device-code phishing flow. In both cases the platform obtained tokens tied to the target’s Microsoft 365 session.

Post-compromise activity, token replay, and persistence

Rather than rely solely on stolen credentials, attackers replayed the captured Microsoft 365 authentication tokens from virtual private servers and commercial VPN infrastructure to access compromised accounts. Once inside, they used Microsoft Graph to enumerate Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications. ZeroBEC recorded access persisting for more than two weeks in some cases.

What this means for security teams, affected enterprises, and end users

  • Security teams: ZeroBEC recommends auditing safe-sender lists and replacing blanket domain exclusions with rules that require valid email authentication. Teams are also advised to hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins originating from hosting providers or VPN addresses.
  • Affected enterprises and administrators: If compromise is suspected, administrators should revoke all access and refresh tokens, and review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services to identify lateral or persistent access.
  • End users: Visual cues included in the campaign — a fake verification banner and realistic voicemail or HR-style lures — underline the need for skepticism about unexpected messages that ask recipients to follow links or approve sign-in prompts.

ZeroBEC also flagged a possible link between the campaign’s target list and RingCentral’s July 28 disclosure — the company said a data incident affecting a “limited portion” of customers had been claimed by the actor ShinyHunters — but researchers cautioned that a confident connection between that incident and Greatness’s targeting cannot be made.

Two ancillary data points from the source material underscore broader detection challenges: the Greatness service’s availability for a monthly fee and a Picus whitepaper finding cited in the same advisory that security teams log 54% of successful attacks but alert on only 14%. Both details reinforce how commoditized tooling and gaps in alerting can let sophisticated phishing flows move from inbox to breach.

The immediate operational takeaway is concrete: attackers are chaining social engineering, whitelisting misconfigurations, and token-based access to sidestep layered defenses. Organizations should treat safe-sender lists and domain exclusions as active risk vectors, hunt for anomalous MFA approvals from hosting and VPN ranges, and be prepared to revoke tokens and audit Microsoft Graph activity when suspected compromise occurs. Whether the RingCentral incident directly seeded Greatness’s target list remains unresolved — but the campaign itself is a demonstrable escalation in phishing-as-a-service tradecraft.

Original story