By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Phishing Service Targets Microsoft 365 Via RingCentral Spoofing
The Greatness phishing-as-a-service (PhaaS) platform has evolved its attack vectors to include sophisticated methods targeting Microsoft 365 accounts, moving beyond basic credential harvesting. This platform, identified by security researchers, now employs adversary-in-the-middle (AiTM) techniques and device-code phishing. A key tactic involves spoofing RingCentral, a widely used cloud communications and collaboration solution, to trick victims into compromising their Microsoft 365 credentials. By impersonating RingCentral, the attackers leverage the trust users place in legitimate business communication tools to facilitate their malicious activities. This allows them to intercept authentication codes and session cookies, granting them unauthorized access to user accounts and sensitive data within the Microsoft 365 ecosystem.
Previously, Greatness was known for simpler credential phishing operations. However, its recent advancements demonstrate a significant escalation in its capabilities and the complexity of its attacks. The integration of AiTM attacks means that Greatness can now potentially capture not only usernames and passwords but also session tokens, which are crucial for maintaining logged-in states. This bypasses traditional multi-factor authentication (MFA) by stealing the active session itself. Furthermore, the platform's adoption of device-code phishing, a method often used to authenticate applications or services to an account, adds another layer of sophistication. This technique typically involves a user being prompted to visit a specific URL and enter a code displayed on another device, a process that attackers can manipulate to gain access.
The targeting of Microsoft 365 is particularly significant due to the platform's widespread adoption by businesses globally. Microsoft 365 encompasses a suite of productivity and collaboration tools, including Outlook, Teams, SharePoint, and OneDrive, which often contain highly sensitive corporate data. Compromising a Microsoft 365 account can lead to extensive data breaches, financial fraud, and significant reputational damage for affected organizations. The Greatness platform's ability to leverage a trusted third-party service like RingCentral as a lure highlights a growing trend in phishing attacks that exploit the interconnectedness of modern business software.
Security experts advise organizations to remain vigilant against such sophisticated phishing campaigns. This includes educating employees about the risks of clicking on suspicious links or providing credentials through unsolicited communications, even if they appear to originate from trusted vendors. Implementing robust security measures, such as advanced threat protection for email and cloud services, regular security awareness training, and strict access controls, is crucial in mitigating the impact of these evolving threats. The continuous adaptation of platforms like Greatness underscores the need for ongoing innovation in cybersecurity defenses to counter increasingly complex adversary tactics.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.