Greatness Phishing Service Spoofs RingCentral to Steal Microsoft 365 Accounts
The Greatness phishing service now impersonates RingCentral to steal Microsoft 365 accounts through adversary-in-the-middle and device-code attacks.
Greatness initially operated as a traditional credential-stealing phishing service. It has since evolved into a broader platform that can capture authentication tokens and bypass some forms of multifactor authentication.
Campaigns have primarily targeted users in the United States, Canada, the United Kingdom, Australia, and South Africa. The platform has also expanded beyond Microsoft 365 to support attacks against iCloud, Yahoo, and Google Workspace accounts.
Attackers impersonate RingCentral notifications
ZeroBEC researchers observed Greatness operators exploiting RingCentral’s trusted status to bypass email security protections.
The attackers spoofed the service@ringcentral[.]com address and sent malicious emails to legitimate RingCentral customers. The messages appeared as voicemail notifications or employee performance-review alerts.
Each email included a fabricated notice claiming that the sender had received approval through the organization’s safe-sender list. This message made the emails appear more trustworthy and encouraged recipients to click an embedded button.
According to ZeroBEC, Microsoft Exchange assigned the messages a Spam Confidence Level of -1. That classification allowed the emails to avoid normal spam filtering.
Greatness steals Microsoft 365 authentication tokens
Clicking the malicious button redirected victims to infrastructure controlled by Greatness operators.
Some victims reached a Microsoft adversary-in-the-middle phishing page. The page captured authentication tokens after the user completed an MFA request.
Other victims entered a device-code phishing process, which persuaded them to authorize an attacker-controlled session through Microsoft’s legitimate authentication system.
After gaining access, the attackers reused stolen Microsoft 365 tokens through virtual private servers and commercial VPN services. This allowed them to enter compromised accounts without completing another standard sign-in.
Attackers search emails, Teams chats, and cloud files
The attackers searched Outlook mailboxes and Microsoft Teams conversations after compromising an account.
They also accessed SharePoint sites, OneDrive files, contacts, calendars, and registered applications. Much of the information was collected through Microsoft Graph.
In some cases, the unauthorized access remained active for more than two weeks, giving the attackers time to search for sensitive business information and identify additional targets.
Researchers examine possible RingCentral breach connection
RingCentral recently confirmed a separate data breach claimed by the ShinyHunters threat group. The company said the incident affected information belonging to a limited number of customers and that it was contacting them directly.
ZeroBEC believes Greatness users may have obtained a list of valid RingCentral customers from that breach. However, the researchers could not confirm a direct connection between the incidents.
Organizations should review email allowlists
Security teams should review safe-sender lists and email allowlists for overly broad exceptions. Organizations should replace blanket domain exclusions with rules that also require valid SPF, DKIM, and DMARC authentication.
Administrators should also investigate unusual MFA-approved Microsoft 365 sign-ins from hosting providers, virtual private servers, or commercial VPN addresses.
When administrators suspect a compromise, they should immediately revoke active access and refresh tokens. They should also review OAuth permissions, Microsoft Graph activity, registered applications, and access across Microsoft 365 services.
In other security news, Microsoft uncovered a global hotel Wi-Fi malware campaign and limited NuGet API key lifetimes to 30 days.
Malware has also discovered new techniques that can steal Google passkeys, raising additional concerns about the security of passwordless authentication systems.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages