Social EngineeringBleeping Computer
8.5 — CRITICAL
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
The Greatness phishing-as-a-service platform has been used to spoof RingCentral and steal Microsoft 365 accounts, targeting users in multiple countries with a Spam Confidence Level of -1 on Microsoft Exchange.
⚙️Technical Details
Affected Systems
Microsoft 365RingCentral communications platform
Attack Vectors
adversary-in-the-middle (AiTM) phishing flowdevice-code phishing flow
💥Impact Assessment
Severity: high
Who Is at Risk
Users of Microsoft 365 and RingCentral communications platforms in the United States, Canada, the UK, Australia, and South Africa
🛡️Recommended Actions
1Audit safe-sender lists and replace blanket domain exclusions with rules requiring valid email authentication
2Hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses
3Revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services
📦Affected Products
Microsoft 365RingCentral communications platform
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
