Greatness operator dashboard
At a glance
| Actor or group | Operators of the Greatness kit, also tracked as HoneyStorm |
| Activity type | Phishing-as-a-Service with AiTM token theft and device code phishing |
| Targets or victims | Microsoft 365, iCloud, Yahoo, and Google Workspace accounts |
| Scale | 3,220 Telegram subscribers; 50+ campaigns since April 2026 |
| Jurisdiction or status | No public law-enforcement action reported |
| Source | ZeroBEC threat research |
TL;DR
ZeroBEC researchers gained access to the Greatness PhaaS platform, a phishing kit sold on Telegram. It steals Microsoft 365 sign-in tokens in real time, even after multi-factor authentication. One live campaign slipped past email gateways by abusing a customer’s own safe sender list.
What happened
The investigation started with four phishing emails on July 22, 2026. Each posed as a RingCentral voicemail or performance review. All four failed SPF, DKIM, and DMARC checks. Yet they still reached the inbox.
The reason was a trust setting, not a broken filter. The target had whitelisted the RingCentral domain. That safe sender rule overrode the failed checks. As ZeroBEC notes, “The security stack was not broken. It was working exactly as configured.”
Why the emails got through
Domain-based exclusions tell filters to trust any message claiming to come from a vendor. However, they do not verify that the message truly came from that vendor. Attackers exploit this gap directly.
Inside the Greatness PhaaS platform
Panel access revealed the full operation. The Greatness PhaaS platform sells through a Telegram bot for about 289 dollars per month. It offers a one-day free trial and lists 3,220 channel subscribers. For comparison, a rival kit called Forg365 charges more.
The operator dashboard tracks stolen cookies, compromised accounts, and blocked bots. It also ships more than eleven ready-made lure templates. These cover voicemail, document sharing, and QR code themes. As a result, low-skill operators can launch campaigns fast.
One backend behind many domains
Testing showed all domains share one backend. A single operator token worked across several unrelated sites. That proves a unified platform, not scattered copycats.
How the AiTM phishing kit works
Victims who click enter a five-stage redirect chain. Early stages hide the true destination and screen out researchers. The backend checks for headless browsers, automation tools, and bot User-Agents. Only a real human reaches the final page.
That page is a live adversary-in-the-middle proxy. This AiTM phishing kit does not just copy a login form. It relays the victim’s credentials to the real Microsoft 365 backend in real time. It even passes through the MFA prompt.
When the victim approves the push notification, the attacker captures the approved token.
A second path: device code phishing
Greatness also supports device code phishing. This branch abuses the OAuth device authorization flow. One lure impersonated DocuSign and asked victims to enter a code. Unlike AiTM, this method works asynchronously.
Impact and scale
The stolen token has already cleared MFA. Therefore the attacker replays it from other IP addresses to reach the victim’s account. This is not session hijacking, so impossible-travel rules often stay silent.
Researchers watched operators route this activity through commercial VPNs. They then enumerated Outlook, Teams, SharePoint, and OneDrive through the Graph API. In one case, the same proxy IP kept logging in more than two weeks later.
URLQuery tracks over 50 related campaigns since April 2026 under the “honeystorm” tag. This report confirmed that kit is Greatness. No public arrests or charges have been reported.
How to stay protected
First, revoke tokens, not just passwords. As ZeroBEC warns, “Credential rotation alone is insufficient.” Active and refresh tokens must be revoked in Entra ID.
Next, audit safe sender rules after any vendor breach. Replace blanket domain trust with authentication-conditional rules. Also watch for sign-ins from unexpected IPs that carry valid MFA tokens.
Finally, hunt for known fingerprints. Defenders can search for the redirector’s “just a momment” title typo. Indicators of compromise here stay descriptive on purpose.
The bottom line
The Greatness PhaaS platform shows how phishing has turned into a subscription business. Cheap access and ready lures widen the pool of attackers. Meanwhile, real-time token theft defeats MFA that many teams still treat as a finish line.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.