The Greatness phishing-as-a-service (PhaaS) platform has expanded its capabilities to help cybercriminals target Microsoft 365 accounts through adversary-in-the-middle (AiTM) phishing, device-code attacks, and OAuth consent abuse.
Sold through a Telegram channel for $289 per month, the service gives operators a centralized dashboard, campaign statistics, configurable domains, CAPTCHA options, and more than 11 pre-built lure templates.
Greatness has targeted Microsoft 365 users since at least mid-2022, but its newer functions show a shift away from simple password theft.
Attackers now aim to capture session cookies and OAuth tokens, which can provide access to cloud services even after a victim has completed multi-factor authentication (MFA).
Greatness Phishing Kit Exposed
The platform reduces the technical skills needed to launch convincing phishing operations.
Its available templates imitate common business workflows, including voicemail alerts, document-sharing notifications, QR-code messages, OneDrive files, video players, and audio-login pages.
The templates include pre-built HTML files, PDF redirectors, SVG content, and letter-style lures, allowing an operator to deploy campaigns without designing phishing pages from scratch.

Greatness also supplies an operator-specific domain and tools for choosing the phishing domain, background theme, CAPTCHA type, and the way stolen cookies are saved.
This service model turns phishing into a subscription product: customers can focus on selecting targets and distributing emails while the platform provides the underlying infrastructure.
Researchers said recent campaigns used spoofed RingCentral voicemail emails to target organizations that genuinely use RingCentral services.
The messages reportedly exploited trusted-sender exclusions in email environments, reaching inboxes even when the messages failed SPF, DKIM, and DMARC validation.
This demonstrates the danger of broad email allowlisting rules based solely on a trusted vendor’s domain.

Victims who click a malicious link can be passed through a five-stage redirect chain. The chain uses anti-analysis checks, browser fingerprinting, and CAPTCHA gates before sending the target to an AiTM proxy page or a device-code phishing endpoint.
These controls make automated scanning and casual investigation more difficult, while helping attackers filter out security researchers and sandbox systems.
In an AiTM attack, a malicious proxy sits between the victim and the legitimate Microsoft sign-in service. It relays the login process in real time, enabling attackers to capture credentials and authenticated session cookies.
A stolen session token can be more valuable than a password because it may let an attacker reuse an already authenticated session without triggering another MFA request, zerobec said.
| Aspect | Details |
|---|---|
| Threat | Greatness phishing-as-a-service (PhaaS) platform |
| Cost | $289 monthly subscription |
| Primary targets | Microsoft 365 users; the platform also supports campaigns targeting iCloud, Yahoo, and Google Workspace |
Greatness now also supports device-code phishing, which abuses the legitimate OAuth 2.0 Device Authorization Grant. Victims receive a convincing reason to visit a real Microsoft verification page and enter a supplied device code.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR