ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

Greatness phishing-as-a-service mimics RingCentral to hijack M365 accounts

Source headline: Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

The Greatness phishing-as-a-service (PhaaS) platform is targeting Microsoft 365 users. It has expanded from stealing credentials to adversary-in-the-middle and device-code phishing. The campaign spoofs RingCentral communications to lure victims into authentication flows. Successful victims can have their Microsoft 365 accounts accessed or tokens abused. Organizations using Microsoft 365 should strengthen phishing defenses, monitor unusual sign-in behavior, and enforce stronger authentication controls.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#phishing #microsoft-365 #device-code-phishing #phaas #adversary-in-the-middle #ringcentral
Original reporting BleepingComputer Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Open original source