Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service platform is now abusing RingCentral's trusted sender reputation to bypass email filters and harvest Microsoft 365 credentials via adversary-in-the-middle and device-code attacks.
Intelligence analysis by Llama

Greatness, a $289/month PhaaS sold on Telegram, has added RingCentral spoofing to its Microsoft 365 attack kit. By impersonating service@ringcentral.com, operators achieve an SCL of -1 on Exchange, slip past filters, and steal MFA-approved tokens for mailbox and Teams access lasting weeks.
Imagine a burglar who dresses up as the mailman. Because the building trusts mail carriers, nobody checks his ID. Greatness is that burglar: it pretends to be RingCentral so your email system waves its messages straight through, then tricks workers into handing over the keys to their Microsoft 365 account, including the part that proves it's really them.
Analysis
When a trusted logo becomes the attack surface
Greatness has spent nearly four years iterating on a single business model: lowering the skill floor for stealing cloud credentials. The platform's latest move, observed by ZeroBEC, is to impersonate RingCentral, a communications provider that enterprises routinely whitelist in Exchange, Proofpoint, and Microsoft Defender configurations. Because RingCentral is permitted to send on behalf of its customers, organizations often add the entire ringcentral.com domain to safe-sender lists rather than enumerating the specific sending subdomains. Greatness weaponizes exactly that shortcut, claiming a sender address of service@ringcentral[.]com and using voicemail and performance-review lures that feel routine in a busy office. The result, the researchers report, is a Spam Confidence Level of -1 on Microsoft Exchange, the lowest possible rating, meaning the message is treated as explicitly trusted rather than merely tolerated.
A two-stage kill chain built for the post-MFA era
The phishing flow itself reflects how the credential-theft economy has adapted to widespread multi-factor authentication. Victims who click the embedded button are routed through either a Microsoft adversary-in-the-middle (AiTM) proxy that captures a fully authenticated session token, or a device-code phishing flow that tricks users into entering a code the attacker generated. Both paths defeat the most common forms of MFA because the token or device is legitimate in the eyes of Entra ID. Once inside, the operators use Microsoft Graph to enumerate Outlook mailboxes, Teams chats, SharePoint sites, OneDrive files, calendars, and registered applications, then replay the tokens from VPS and commercial VPN infrastructure so the sign-ins look like ordinary remote work. ZeroBEC observed persistence of more than two weeks in some cases, long enough to stage follow-on business email compromise or to quietly register additional OAuth applications for future access.
The ShinyHunters shadow over RingCentral
A separate thread runs alongside the technical analysis. RingCentral disclosed on July 28 that a data breach claimed by ShinyHunters had affected a limited portion of its customers, and ZeroBEC notes it is likely that Greatness operators obtained a list of valid RingCentral users from that incident to choose targets who would actually be expecting mail from the platform. The researchers stop short of drawing a confirmed link, but the timing and the specificity of the lures make the circumstantial case hard to ignore. The practical lesson is the one ZeroBEC closes on: blanket domain exclusions on safe-sender lists should be replaced with rules that require passing SPF, DKIM, and DMARC, and security teams should hunt for MFA-approved Microsoft 365 sign-ins originating from hosting or VPN ranges, which legitimate users of a cloud PBX rarely produce.
Key points
- Greatness PhaaS, sold for $289 per month on Telegram, now spoofs RingCentral to bypass email security filters against Microsoft 365 targets.
- Spoofed messages claiming to be from service@ringcentral[.]com achieved an SCL of -1 on Microsoft Exchange by exploiting safe-sender whitelists.
- The campaign uses adversary-in-the-middle and device-code phishing to capture MFA-approved authentication tokens, then replays them from VPS and VPN infrastructure.
- Post-compromise access to Outlook, Teams, SharePoint, OneDrive, and registered apps via Microsoft Graph persisted for more than two weeks in some cases.
- ZeroBEC suggests operators may have obtained RingCentral user data from a July 28 breach disclosed by the company and claimed by ShinyHunters, though no confirmed link has been established.
The incident gives security teams a concrete, observable signal to hunt for: MFA-approved Microsoft 365 sign-ins from hosting or VPN IP ranges tied to Greatness infrastructure, which most legitimate RingCentral users will not generate. Replacing blanket domain whitelists with authentication-passed rules, as ZeroBEC recommends, would close the immediate bypass and reduce the blast radius of similar future spoofs.
Because Greatness already exfiltrates valid session tokens and reuses them from clean infrastructure, a single employee click can grant attackers weeks of mailbox and Teams access even after the phishing email is reported and deleted. If the RingCentral-ShinyHunters link is real, the operators may also have a vetted target list, making the next campaign harder to filter on the recipient side.


