npx shadcn@latest add https://www.vengenceui.com/r/animated-button.json
top of page
Dc Cybertech logo
Search

Cyber Criminals Target Microsoft 365 Credentials in Sophisticated RingCentral Phishing Campaign

Microsoft 365 users are facing a heightened security threat as cyber criminals launch targeted phishing campaigns designed to compromise enterprise accounts, even those safeguarded by multi-factor authentication (MFA). Security researchers at ZeroBEC have identified an active operation exploiting spoofed RingCentral communications to breach corporate networks across several major international jurisdictions.


The attack vector relies on "Greatness", a rapidly evolving Phishing-as-a-Service (PhaaS) platform operating via Telegram networks. Whilst Greatness initially functioned as a basic credential-harvesting tool, its latest updates permit malicious actors to bypass standard secondary security controls by capturing live, MFA-approved authentication tokens in real time.


Exploiting the RingCentral Breach Infrastructure

The current campaign appears to capitalize on a previous security incident involving cloud communications provider RingCentral, which was compromised by the threat actor collective known as ShinyHunters. Although formal confirmation remains pending, security analysts suspect that threat actors are deploying email registries exfiltrated during that breach to select prospective corporate victims.


Targeted individuals receive emails designed to closely imitate authentic RingCentral system notifications, including alerts regarding missed voicemails or internal performance evaluations. Despite originating from unverified mail servers and failing basic Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting, and Conformance (DMARC) validation checks, the convincing social engineering lures frequently bypass basic user suspicion.



Adversary-in-the-Middle Mechanics and Token Capture

Upon selecting the embedded link within the fraudulent message, the user is directed to adversary-controlled infrastructure hosting a replicated Microsoft 365 sign-in interface.


When the victim inputs their login credentials alongside their secondary MFA prompt, the Greatness service intercepts the interaction using an Adversary-in-the-Middle (AiTM) architecture. The platform captures the valid session token issued by the authentic identity provider, effectively giving the attacker direct access without needing the victim's static password again.


This session hijacking grants threat actors unrestricted access to core enterprise productivity applications, including Outlook, Teams, SharePoint, and OneDrive. Beyond Microsoft ecosystem environments, ZeroBEC reports that the PhaaS platform has widened its scope to intercept sessions for Google Workspace, Yahoo, and Apple iCloud accounts.


Distribution Model and Regional Exposure

Greatness functions via a commercial cybercrime model, lowering the technical entry point for low-skilled actors. Marketed across public and private Telegram channels containing thousands of subscribers, access to the platform is currently rented for approximately $289 per month.


According to ZeroBEC tracking, Greatness has maintained operational activity for at least four years, maintaining a consistent focus on targets in the United Kingdom, the United States, Canada, Australia, and South Africa.


Security professionals recommend reinforcing identity perimeter controls through FIDO2-compliant hardware keys, enforcing strict conditional access rules, and continuously reviewing mail gateway logs to catch incoming DMARC and SPF verification failures before fraudulent messages reach inbox destinations.

 
 
 
bottom of page