North America
Microsoft 365 users
A sophisticated phishing campaign is using the Greatness phishing-as-a-service (PhaaS) platform to target Microsoft 365 accounts by impersonating RingCentral notifications.
Greatness is a subscription-based PhaaS platform that has been active since at least 2022, providing cybercriminals with ready-to-use phishing toolkits. The platform has now expanded beyond credential phishing to adversary-in-the-middle (AiTM) attacks and device-code phishing targeting Microsoft 365 accounts. In a recent campaign observed by researchers, Greatness operators are abusing the RingCentral communications platform to bypass recipients' email security filters. Attackers impersonate RingCentral by claiming messages originate from service@ringcentral[.]com and target actual users of the service with fake voicemail and performance-review notifications designed to entice them to open the emails.
Although the messages originate from an unknown IONOS mail server, fail SPF and DMARC checks and lack a DKIM signature, they are still accepted by receiving systems because RingCentral is whitelisted. The emails also include a fraudulent banner claiming the sender has been verified through the organization's safe-sender list, further reducing suspicion and making the phishing messages appear more credible to recipients.
How it could affect your business
Greatness PhaaS is currently being offered to cybercriminals for less than $300 per month through a Telegram channel with thousands of subscribers. Such as-a-service platforms lower the barrier to cybercrime, enabling even attackers with limited technical expertise to launch sophisticated phishing campaigns at scale. Organizations should prioritize ongoing user awareness training to help employees recognize evolving phishing tactics, question seemingly trusted communications and verify suspicious requests before taking action.
