Greatness: Telegram-Distributed M365 AiTM PhaaS

speckx1 pts0 comments

Inside Greatness: Telegram-Distributed M365 AiTM PhaaS | ZeroBEC

ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. This investigation began with a live campaign that exploited spoofed RingCentral emails and customer-side safe sender exclusions to bypass email gateway controls and deliver phishing lures targeting Microsoft 365 accounts. Panel access, infrastructure testing, and cross-domain analysis revealed the full operator ecosystem, shared backend, and post-compromise tradecraft.

Executive summary

Greatness is a known phishing-as-a-service platform first documented by Cisco Talos in May 2023, with earlier and concurrent coverage by Hornet Security and Trellix. Since its initial discovery, the platform has evolved significantly. It now supports adversary-in-the-middle (AiTM) credential and token theft, device code phishing, and targets across multiple platforms including Microsoft 365, iCloud, Yahoo, and Google Workspace.

This investigation began when a live Greatness campaign targeted a ZeroBEC-protected organization using spoofed RingCentral voicemail lures. The campaign exploited vendor trust, specifically, domain-based safe sender exclusions, to bypass email gateway controls entirely. All four phishing emails failed every standard email authentication check yet were delivered to the inbox because the target organization had whitelisted the spoofed vendor domain.

Panel access revealed the full operator ecosystem: Greatness is distributed via Telegram with a $289/month subscription, lower than the $400/month observed for Forg365, with a 1-day free trial and 3,220 channel subscribers. The operator panel provides a dashboard with campaign statistics, domain configuration, captcha selection, and 11+ downloadable lure templates covering voicemail, document sharing, QR codes, and more.

Testing confirmed that all Greatness domains share centralized backend infrastructure. Operator tokens are interchangeable across domains: a token from one campaign works on any Greatness domain, proving a unified platform architecture. Post-compromise activity was observed through multiple commercial VPN services across different geographies, with operators replaying captured authentication tokens to access victim Microsoft 365 resources.

The kit has since been tracked by Sekoia through built-in detection rules and documented across multiple campaigns in URLQuery. Industry research by HALOCK has highlighted its targeting of financial services organizations. CISA has issued advisories on the broader AiTM phishing threat. The platform shares operational patterns with the broader class of Microsoft 365-focused AiTM PhaaS platforms that ZeroBEC has previously documented, including Forg365, Sneaky 2FA, and DEBULL (Storm-2372).

Naming note. URLQuery tracks these campaigns under the honeystorm tag. This investigation confirmed the underlying kit is Greatness. Defenders should search both Greatness and HoneyStorm when hunting for this threat, as different tracking systems use different names for the same platform.

Key findings

Telegram-distributed PhaaS. Greatness operates at $289/month with a 1-day free trial and 3,220 channel subscribers.

Multi-technique capability. Greatness supports AiTM credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure.

Safe sender exclusion bypass. The investigated campaign used spoofed RingCentral voicemail lures that bypassed email gateways via safe sender exclusions. All emails failed SPF, DKIM, and DMARC but were delivered to the inbox (SCL=-1) because the target organization had whitelisted the vendor domain.

Full operator ecosystem exposed. Panel access exposed the O365 Panel login, dashboard with total cookies/accounts/visits/license days/blocked bots and geo map, domain configuration with captcha selection and bulletproof redirects, and 11+ downloadable lure templates.

Backend panel discovered via device code page source. The poll() JavaScript function called greatwallwebsite[.]blog/admin/apifiles[.]php, revealing the Greatness admin panel.

Cross-domain token interoperability confirmed. Operator token 4am16l1tm works on xdccoc[.]top, nawarra[.]top, and onewayoutolook[.]one, proving all domains share a centralized backend.

Common AiTM proxy observed most often. 38.248.95[.]214 (Limestone Networks/OneProvider VPS, port 8443, Sectigo/Gen Digital certificate) was the most commonly observed post-authentication IP across tested campaigns. Additional hosts with identical fingerprints in 38.248.95[.]0/24 remain candidates for monitoring, and other proxy IPs with the same infrastructure profile have been observed on the platform.

New post-compromise IP. 158.173.166[.]3 (Oslo, Norway, PIA VPN...

greatness aitm phishing operator panel domain

Related Articles