Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay – not password theft – is driving the persistence in this AiTM PhaaS ecosystem.
Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, Trellix, HALOCK, and Sekoia, Greatness has expanded its targeting scope beyond Microsoft 365 to iCloud, Yahoo, and Google Workspace, while maintaining a clear focus on enterprise M365 compromise.
The platform is fully monetized through Telegram, where Greatness operates via a bot and a public channel with 3,220 subscribers, and uses a $289/month subscription model, undercutting comparable AiTM kits such as Forg365 at $400/month.
Operators register through the bot, receive trial licenses, and are provisioned phishing infrastructure using api‑[token].[base‑domain] conventions.
From there, a web-based “O365 Panel” exposes detailed campaign telemetry: total cookies and accounts, visit counts, license days, blocked bots, and geospatial victim mapping, plus configuration controls for domains, captcha, themes, redirect behavior, and 11+ downloadable lure templates spanning voicemail, OneDrive, QR, video, and Windows Explorer themes.
This research began with a live campaign against a RingCentral customer protected by ZeroBEC. Four spoofed voicemail lures, all sent from service@ringcentral[.]com via IONOS infrastructure with no DKIM and failing SPF and DMARC, nonetheless landed in Microsoft 365 inboxes with Spam Confidence Level set to ‑1 (explicitly trusted).
The root cause was not a broken gateway but misconfiguration: domain-based safe sender exclusions that instructed the stack to trust anything claiming to be from ringcentral[.]com, regardless of authentication status.
The attackers exploited this trust explicitly, adding a fraudulent “This sender has been verified by [organization].com safe senders list” banner to preempt suspicion and drive clicks on a Microsoft-styled “Open Message” button.
The choice of RingCentral is strategic. RingCentral is widely deployed, commonly allowed, and recently disclosed a ransomware incident that raised questions about customer data exposure.
Prior work by RingCentral itself, Abnormal Security, JoeSandbox, and others has documented RingCentral-themed phishing, but Greatness adds a critical twist: the lures are not only impersonating RingCentral, they are weaponizing safe sender exclusions that exist because the victims are legitimate RingCentral customers.
The implication extends beyond this vendor – any breach exposing customer lists simultaneously reveals which organizations are likely to be trusting that vendor’s domains unconditionally and therefore susceptible to the same bypass pattern.
Panel access and cross-domain testing confirmed Greatness operates a single, centralized backend across all operator domains.
ZeroBEC’s latest investigation into the Greatness phishing-as-a-service platform shows a mature, commercially operated kit that now combines adversary‑in‑the‑middle credential and token theft, device code phishing, and OAuth consent abuse from a single shared backend.
Tokens issued for one domain (for example, 4am16l1tm on nawarra[.]top) were accepted on others such as xdccoc[.]top and onewayoutolook[.]one, proving unified license validation and infrastructure.
All phishing domains are Cloudflare-fronted, fingerprinted by PHP 8.2.12 Laravel hosting, with wildcard DNS and a consistent JSON error response when licenses expire.
Victims who click the “Open Message” button are routed through a five‑stage chain: a legitimate click‑tracking service, an anti-analysis redirector (finreportviewersoftware[.]sbs) using hex/ROT13/base64 obfuscation and the persistent “just a momment” page title typo.
Greatness API endpoint performing bot and automation detection, a Cloudflare Turnstile-style “Security Verification” gate, and finally either a full Microsoft 365 AiTM proxy or a device code phishing flow.
Stolen Greatness authentication tokens
The AiTM branch relays live Microsoft sign‑in, including MFA number matching, captures valid, MFA‑approved tokens, and then redirects victims to legitimate financial content such as raymondjames[.]com to suppress suspicion.

@GreatnessMGR Telegram profile, the platform administrator and developer handle that manages operator support and platform development (Source : ZeroBEC).The device code branch abuses OAuth device authorization, using a DocuSign-themed lure and a JavaScript poll() function calling greatwallwebsite[.]blog/admin/apifiles[.]php, which exposed the Greatness admin backend and enabled broader ecosystem mapping.
Entra ID sign‑in telemetry from controlled testing shows that Greatness operators are not merely harvesting passwords; they are operationalizing stolen tokens via commercial VPN infrastructure across multiple geographies.
A Limestone Networks VPS at 38.248.95[.]214, fronted as gen‑vpn[.]com, emerges as the most common AiTM proxy and post‑auth sign‑in IP, with sibling hosts in the same /24 exhibiting identical fingerprints.
Additional activity clusters originate from 46.173.240[.]0/24 and 158.173.166[.]0/24 ranges, tied to ExpressVPN, EventVPN/Netshield, and PIA VPN exit nodes, and show systematic Microsoft 365 enumeration via Graph API across Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and registered applications.
The most alarming finding is persistence: more than two weeks after the initial RingCentral-themed phishing wave, the same AiTM proxy IP was still successfully authenticating against the victim’s Microsoft 365 account with no Conditional Access policies applied, demonstrating that AiTM-captured tokens can provide durable.

The security configuration that failed the organization was thus twofold: safe sender exclusions that delivered the phish, and identity-layer controls that focused on credential rotation rather than comprehensive token and refresh token revocation.
URLQuery tracks this activity under the honeystorm tag and has documented more than 50 consistent Greatness campaigns since April 2026, while Sekoia ships built‑in detection rules for the kit.
ZeroBEC’s analysis, combined with prior public research from Cisco Talos, Hornet Security, Trellix, HALOCK, CISA AiTM advisories, and ZeroBEC’s own work on Forg365, Sneaky 2FA, and DEBULL (Storm‑2372), confirms that “HoneyStorm” in some ecosystems is Greatness by another name.
Defenders hunting for this threat should therefore pivot on both Greatness and HoneyStorm nomenclature, infrastructure fingerprints such as “just a momment” redirectors and PHP 8.2.12 Cloudflare domains, and VPN‑hosted proxy IP ranges, while simultaneously auditing vendor-based safe sender lists and enforcing authentication‑conditional trust policies.
IOCs
| Domain | Role |
|---|---|
searchbriefing[.]com | Click tracking / initial redirect |
loading.finreportviewersoftware[.]sbs | Anti-analysis redirector |
api-8g9ezadxs[.]onewayoutlook[.]one | Operator API endpoint |
onewayoutolook[.]one | Greatness phishing domain (typo in domain is intentional by attacker) |
xdccoc[.]top | AiTM credential theft |
nawarra[.]top | AiTM phishing domain (operator token 4am16l1tm) |
saileventpartners[.]top | AiTM phishing domain (operator token 4am16l1tm) |
greatwallwebsite[.]blog | Greatness backend panel / API |
hashmiaghayi[.]cfd | Operator-provisioned phishing domain |
addtoitinnew[.]sbs | Phishing domain from panel |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Why use the 2026 Agentic SOC Buyer’s Guide? 8 Best Platforms Compared – Download the 2026 Buyer’s Guide

