(Image credit: Shutterstock) ZeroBEC observes Greatness PhaaS evolving to bypass MFA and phish Microsoft 365, iCloud, Yahoo, and Google Workspace accountsAttackers spoofed RingCentral emails post‑ShinyHunters breach, luring victims to fake Microsoft 365 logins that capture authentication tokensGreatness is sold on Telegram for $289/month, enabling access to Outlook, Teams, SharePoint, OneDrive, and more across multiple regionsMicrosoft 365 users have been getting phishing emails spoofing RingCentral, designed to steal their accounts even if they were protected by multi-factor authentication (MFA), experts have warned.Security researchers ZeroBEC claim to have observed a phishing-as-a-service (PhaaS) platform called Greatness evolve to also target MFA accounts, as well.Greatness used to be a simple credential phishing platform. However, in recent times, it evolved to target not just Microsoft 365 accounts, but also those of iCloud, Yahoo, and Google Workspace.Grabbing MFA-approved authentication tokensZeroBEC notes that RingCentral recently suffered a data breach at the hands of the infamous ShinyHunters hackers, meaning there is a good chance (although not confirmed) that the threat actors exfiltrated a list of emails belonging to RingCentral customers from that attack, and used it in this attack.Now, RingCentral customers have been getting emails that look as if they are coming from the company itself, despite being mailed from an unknown mail server, and despite failing SPF and DMARC checks. The emails are the standard fake voicemail and performance-review notifications which, if clicked, redirect the victim to attacker-owned infrastructure spoofing the Microsoft 365 login page.Through this malicious landing page, Greatness operators are able to capture MFA-approved authentication tokens, bypassing the login process entirely and moving straight into victim accounts.From there, they would enumerate Outlook mailboxes, Teams conversations, and SharePoint sites. They would also access OneDrive files, contacts, calendars, and registered applications through Microsoft Graph.Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!The number of victims is unknown at the time, but ZeroBEC says Greatness has been active for at least four years now, targeting users in the US, UK, Australia, Canada, and South Africa.According to BleepingComputer, the platform is being advertised for sale on Telegram channels with “thousands of subscribers”, and is currently being offered for a monthly fee of $289.Via BleepingComputer Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
Microsoft 365 users hit by phishing scheme posing as RingCentral emails
Full Article
Original Source
Read the full article at Techradar →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.