The Greatness phishing platform has evolved beyond credential theft by adopting AiTM phishing and device-code phishing techniques to compromise Microsoft 365 accounts. A recent campaign spoofed RingCentral notifications to bypass email filtering and steal authentication tokens instead of passwords. Since stolen tokens can bypass traditional MFA protections, organizations should strengthen identity security, monitor Microsoft 365 activity, audit trusted sender lists, and secure endpoints with unified identity and device controls.
Cybercriminals continue to refine phishing techniques, and the latest Greatness phishing campaign demonstrates how attackers can compromise Microsoft 365 accounts without relying solely on stolen passwords. By spoofing RingCentral notifications and abusing trusted sender configurations, attackers trick users into authentic-looking Microsoft login flows that capture valid authentication tokens.
The campaign highlights a growing enterprise security challenge. Traditional email filtering and MFA are no longer sufficient when attackers steal session tokens or exploit legitimate authentication workflows. Organizations must secure identities, devices, and cloud workloads together to reduce exposure.
Researchers recently observed the Greatness phishing-as-a-service (PhaaS) platform expanding beyond credential theft into AiTM phishing and device-code phishing attacks targeting Microsoft 365 users.
The attackers distributed phishing emails disguised as:
RingCentral voicemail notifications
Employee performance review alerts
Although the emails failed SPF and DMARC validation and lacked DKIM signatures, many still reached users because RingCentral domains had been broadly trusted in recipient-side allowlists. Microsoft Exchange assigned the messages a Spam Confidence Level (SCL) of -1, indicating they were bypassed by safe-sender logic despite failing standard email authentication checks. This allowed malicious emails to evade recipient-side filtering.
Once victims clicked the embedded links, they were redirected to attacker-controlled infrastructure supporting multiple Microsoft 365 phishing techniques.
Attack stage
Description
Initial lure
Fake RingCentral notifications
Email bypass
Trusted sender logic accepted unauthenticated mail
Credential stage
Victims redirected to Microsoft-themed phishing pages
Account compromise
Authentication tokens captured using AiTM or device-code flows
Post-compromise
Microsoft Graph used to access organizational data
AiTM phishing and device-code phishing enable MFA bypass
Unlike traditional phishing, AiTM phishing places an attacker-controlled proxy between the user and Microsoft. The victim completes a legitimate authentication flow, including MFA, while the attacker captures the authenticated session token.
Instead of stealing only passwords, attackers obtain reusable authentication tokens that provide immediate access to Microsoft 365 resources.
The campaign also employed device-code phishing, which abuses Microsoft’s OAuth 2.0 Device Authorization Grant workflow. This authentication flow is designed for devices with limited input capabilities, allowing users to authorize a session by entering a device code on Microsoft’s sign-in page. Attackers exploit this legitimate process by tricking victims into entering attacker-generated device codes, unknowingly granting the attacker access to their Microsoft 365 session.
Both approaches enable an effective MFA bypass because attackers leverage valid authentication rather than attempting to defeat the MFA mechanism itself.
After gaining access, attackers used Microsoft Graph APIs to enumerate:
Outlook mailboxes
Teams conversations
SharePoint sites
OneDrive files
Contacts
Calendars
Registered Microsoft 365 applications
OAuth permissions
This broad visibility enables data theft, business email compromise, and additional lateral movement throughout Microsoft 365 environments.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
How Hexnode helps reduce identity-based phishing risks
Modern phishing campaigns demonstrate that identity security and device security cannot operate in isolation. While Microsoft Entra ID helps protect identities through authentication, Conditional Access, and sign-in risk analysis, organizations also need trusted endpoint management to ensure only secure, compliant devices can access corporate resources. Together, identity controls and device posture provide stronger protection against modern token-based attacks.
Hexnode XDR correlates behavioral signals across endpoints, enriches alerts with device and UEM context, maps detected attack chains to MITRE ATT&CK, and allows analysts to investigate historical process and endpoint-event data.
These correlated endpoint signals help analysts investigate detected threats and take containment actions such as isolating devices, terminating malicious processes, or quarantining files.
Hexnode UEM complements identity security by enforcing security controls on managed devices, including:
Secure browser configuration policies
Device compliance enforcement
Trusted device access controls
Endpoint security baselines
Organizations can also strengthen Microsoft 365 protection by allowing access only from trusted, compliant, and managed devices.
Hexnode UEM can integrate with Microsoft Entra Conditional Access to control access to enterprise resources based on Hexnode device compliance, while Office 365 access can also be restricted to enrolled devices through supported Conditional Access configurations.
Best practices to defend against Greatness phishing
Security teams should treat token theft with the same urgency as credential theft.
Recommended defensive measures include:
Audit safe-sender and email allowlists regularly.
Replace broad domain allowlisting with authenticated-mail validation rules.
Monitor Microsoft 365 sign-ins originating from hosting providers, VPS infrastructure, or VPN services.
Investigate unusual MFA-approved sessions.
Revoke active authentication tokens immediately after suspected compromise.
Review OAuth consent grants and Microsoft Graph activity.
Limit Microsoft 365 access to compliant, managed devices.
Continuously monitor endpoint and identity telemetry for post-compromise behavior.
These layered controls reduce the impact of phishing campaigns that target authentication tokens instead of passwords.
FAQs
What is Greatness phishing?
Greatness phishing is a phishing-as-a-service (PhaaS) platform that targets Microsoft 365 users. It supports advanced techniques such as AiTM phishing and device-code phishing to steal authentication tokens instead of only usernames and passwords.
What is device-code phishing?
Device-code phishing abuses Microsoft’s legitimate device authorization process. Attackers convince users to enter a valid device code on Microsoft’s login page, unknowingly granting attackers access to their Microsoft 365 accounts.
How does AiTM phishing bypass MFA?
AiTM phishing captures authenticated session tokens after users complete legitimate MFA. Since attackers reuse valid authentication tokens rather than passwords, they can effectively achieve an MFA bypass without breaking the MFA mechanism itself.
Why should organizations monitor Microsoft Graph activity?
Attackers often use Microsoft Graph after compromising Microsoft 365 accounts to enumerate mailboxes, Teams data, SharePoint sites, OneDrive files, contacts, calendars, and application permissions. Monitoring Graph activity helps identify abnormal post-compromise behavior early.
How does device compliance help reduce the risk of stolen authentication tokens?
Microsoft Entra Conditional Access can use Hexnode device compliance as a condition for granting access to Microsoft 365 resources. If an attacker attempts to reuse a stolen authentication token from an unmanaged or non-compliant device, Conditional Access policies can deny access because the device does not satisfy the organization’s compliance requirements. While device compliance does not prevent token theft itself, it helps limit the usefulness of stolen tokens by enforcing access only from trusted, managed devices.
Conclusion
The latest Greatness phishing campaign demonstrates how phishing attacks continue to evolve beyond credential theft. By combining AiTM phishing, device-code phishing, and trusted sender abuse, attackers can obtain Microsoft 365 authentication tokens and maintain access even after MFA succeeds.
Organizations should strengthen email trust policies, monitor token-based attacks, secure Microsoft 365 identities, and combine identity security with endpoint visibility. A layered security approach that integrates IAM, endpoint management, and XDR provides stronger protection against modern phishing campaigns.
Protect Microsoft 365 Identities
Detect token theft, enforce trusted device access, and strengthen identity security with Hexnode UEM and XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.