top of page
perceptive_background_267k.jpg

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Published:

4 augustus 2026 om 21:45:36

Alert date:

4 augustus 2026 om 22:03:03

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Identity & Access, Email & Messaging, Data Breach & Exfiltration, Ransomware & Malware

The Greatness phishing-as-a-service (PhaaS) platform has evolved beyond simple credential phishing to include adversary-in-the-middle (AiTM) attacks and device-code phishing. The platform specifically targets Microsoft 365 accounts by spoofing RingCentral communications. This expansion represents a significant escalation in the capabilities offered by the Greatness PhaaS platform. The service allows cybercriminals to conduct sophisticated phishing campaigns without advanced technical knowledge. By impersonating RingCentral, attackers lure victims into entering their Microsoft 365 credentials. The AiTM technique allows attackers to bypass multi-factor authentication by intercepting session tokens. Device-code phishing is an additional method used to gain unauthorized access to accounts.

Technical details

The Greatness phishing-as-a-service (PhaaS) platform has evolved from credential phishing to adversary-in-the-middle (AiTM) attacks and device-code phishing targeting Microsoft 365 accounts. Active since at least mid-2022, it is sold for $289/month via a Telegram channel. In a recent campaign, operators impersonated RingCentral by spoofing the sender address as service@ringcentral[.]com. Emails used fake voicemail and performance-review notifications as lures. Though originating from an unknown IONOS mail server, failing SPF and DMARC checks, and lacking a DKIM signature, the emails bypassed email security filters because RingCentral was whitelisted, achieving a Spam Confidence Level (SCL) of -1 on Microsoft Exchange. Emails also included a fraudulent banner claiming sender verification. Victims clicking embedded links were routed to Greatness infrastructure where they encountered either a Microsoft AiTM phishing flow (capturing MFA-approved authentication tokens) or a device-code phishing flow. Post-compromise, attackers replayed Microsoft 365 authentication tokens from VPS and commercial VPN infrastructure to access accounts. They then enumerated Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications via Microsoft Graph, with persistence lasting more than two weeks in some cases. It is suspected that victim targeting may have leveraged data from a RingCentral data breach claimed by threat actor ShinyHunters (disclosed July 28).

Mitigation steps:

1. Audit safe-sender lists and replace blanket domain exclusions with rules requiring valid email authentication (SPF, DKIM, DMARC). 2. Hunt for Greatness phishing infrastructure indicators within the environment. 3. Monitor for suspicious MFA-approved Microsoft 365 sign-ins originating from hosting providers or commercial VPN addresses. 4. If compromise is suspected: revoke all access and refresh tokens immediately; review OAuth consent grants; audit Microsoft Graph activity logs; review access to all Microsoft 365 services. 5. Monitor for unusual enumeration of Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications. 6. Educate users to be suspicious of voicemail and performance-review email lures, especially those claiming sender verification.

Affected products:

Microsoft 365
Microsoft Exchange
Microsoft Outlook
Microsoft Teams
Microsoft SharePoint
Microsoft OneDrive
Microsoft Graph API
iCloud
Yahoo Mail
Google Workspace
RingCentral

Related links:

Related CVE's:

Related threat actors:

IOC's:

service@ringcentral[.]com (spoofed sender address), IONOS mail server (origin of phishing emails), SCL of -1 on Microsoft Exchange (indicator of safe-sender bypass), MFA-approved Microsoft 365 sign-ins from VPS or commercial VPN addresses, Suspicious Microsoft Graph API enumeration activity (Outlook, Teams, SharePoint, OneDrive, contacts, calendars, OAuth apps)

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page