Researchers at ZeroBEC are tracking a phishing platform called “Greatness” that’s been significantly upgraded since it surfaced in 2023.
“Since its initial discovery, the platform has evolved significantly,” the researchers write. “It now supports adversary-in-the-middle (AiTM) credential and token theft, device code phishing, and targets across multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace.”
The platform’s operators can launch both AiTM attacks or device code phishing attacks to bypass multi-factor authentication.
“The device code phishing approach complements the AiTM technique,” ZeroBEC says. “While AiTM requires real-time interaction and proxy infrastructure, device code phishing is asynchronous. The attacker generates codes in advance, and the victim's approval can happen at any time. This dual capability gives Greatness operators flexibility to choose the most appropriate technique based on their target and campaign goals.”
Notably, all of the phishing emails observed by ZeroBEC were delivered to end users because the targeted organization had marked all RingCentral domains as safe.
“RingCentral's published email policy demands rejection of unauthenticated messages with 100% enforcement,” the researchers write. “Under normal conditions, these emails should have been rejected at the gateway. Instead, all four were delivered to the inbox. The target organization is a legitimate RingCentral customer and has added the domain to its safe-sender configuration across its email security stack. This domain-based exclusion overrode the authentication failure, instructing the security controls to treat the spoofed messages as trusted. The messages were assigned a Spam Confidence Level of -1 (safe), bypassing all subsequent filtering.”
Zero BEC has the story: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
