The Greatness platform has integrated device code phishing into its MFA bypass arsenal, combining it with credential and token theft via AiTM proxy and OAuth consent abuse in a single operator interface. The ZeroBEC analysis published on August 11, 2026 documents the shared infrastructure that makes operator tokens interoperable across different domains, lowering the technical barrier for less sophisticated attackers. The discovery confirms the maturation of the PhaaS model from isolated kits to a SaaS-like platform with multiple integrated compromise techniques.
- Greatness combines AiTM credential theft, device code phishing, and OAuth consent abuse in the same operator interface with a centralized backend.
- Operator tokens are interoperable cross-domain: a single '4am16l1tm' token works across multiple phishing domains, proving shared infrastructure.
- The device code flow exploits legitimate Microsoft OAuth functionality, making detection based on malicious URLs harder.
- Domain-based safe sender exclusions — not conditional authentication — allowed full email gateway bypass despite SPF, DKIM, and DMARC failures.
The Live Campaign: Four Emails in Seconds, All "Safe" by Configuration
The ZeroBEC analysis originated from a campaign observed on July 22, 2026: four phishing emails delivered to the same organization within seconds, all with a spoofed sender service@ringcentral.com and a personalized subject line. The four emails were quarantined by the research system, but their passage through the target network reveals a systematic bypass mechanism.
The dossier shows SPF, DKIM, and DMARC results all failed. Despite this, the emails were classified with SCL -1: "message explicitly marked as safe, all filtering bypassed." The cause is documented in logs as "action overridden by safe sender exclusion." The exclusions were configured by domain — trusting any email claiming origin from ringcentral.com — rather than by conditional authentication.
As the ZeroBEC analysis underscores: "The security stack was not broken. It was working exactly as configured. The vulnerability was the configuration itself." The Greatness platform exploits this human-organizational flaw by combining it with advanced technical techniques, creating an attack where security works exactly as configured, and that configuration is wrong.
The Centralized Backend: Discovered via Device Code Page Source
Greatness stands out for its centralized architecture, not isolated domains. Analysis of the device code page revealed the JavaScript poll() function calling greatwallwebsite[.]blog/admin/apifiles[.]php, exposing the administrative panel. From this discovery, researchers verified cross-domain interoperability: the operator token '4am16l1tm' was valid on xdccoc[.]top, nawarra[.]top, and onewayoutolook[.]one, demonstrating that all domains share the same backend.
The administrative panel hosts at least 11 downloadable lure templates for operators: AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer. New phishing domains identified from the panel include hashmiaghayi[.]cfd, addtoitinnew[.]sbs, willgrantitinfewsecondafter[.]cfd, lookatemailplease[.]one, and pleasebepatienttoload[.]sbs. This tooling standardization is the hallmark of the mature PhaaS model: the operator buys access, selects a template, and gains cross-domain interoperability without managing their own infrastructure.
Post-Compromise: Commercial VPNs and Microsoft 365 Enumeration
After initial access, operators documented by ZeroBEC use at least three commercial VPN services: ExpressVPN, EventVPN/Netshield, and PIA. IP 158.173.166[.]3, associated with PIA with an Oslo exit node, was observed on August 2, 2026 for post-compromise activity. The most common AiTM proxy in the analyzed campaign resides at 38.248.95[.]214, a Limestone Networks/OneProvider VPS on port 8443.
Post-compromise activity includes Microsoft 365 enumeration via Microsoft Graph API from subnet 46.173.240[.]0/24, targeting Outlook, Teams, SharePoint, Exchange, and OneDrive. Victims, after credential theft, are redirected to legitimate raymondjames[.]com documents as a benign decoy. This sequence — phishing, token capture, persistent API access, decoy — is executed through the centralized Greatness interface without requiring development skills from the operator.
"Greatness supports AiTM credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure"
Historical Context: From Cisco Talos to Sekoia, Tracking an Evolving Platform
Greatness has been documented since 2022: the Cisco Talos report from May 2023, cited by BleepingComputer and HALOCK, traces its launch to mid-2022, with activity peaks in December 2022 and March 2023. Historical campaigns primarily targeted manufacturing, healthcare, and technology sectors in the United States, United Kingdom, Australia, South Africa, and Canada. The financial services sector aligns with HALOCK research, which places Greatness in the crosshairs of financial institutions.
URLQuery tracks Greatness campaigns with the 'honeystorm' tag, with over 50 campaigns documented since April 2026 according to the ZeroBEC source. Sekoia documents the platform via dedicated detection rules, with specific rules for Microsoft Entra ID Device Code Authentication. This multi-source presence in threat intelligence feeds — despite the anomalous date of the primary analysis — confirms the platform's operational persistence over time.
Why It Matters
The dossier does not specify specific remedial measures for target organizations. It does not emerge whether Microsoft has classified the device code flow as high-risk in the context of Greatness, although the OAuth functionality is a known abuse vector. The primary source does not document Greatness's pricing model, nor whether it matches the Forg365 model cited as sector context ($400 monthly, $3,800 annually). The exact number of victims of the device code variant is not stated.
The ZeroBEC analysis date — August 4, 2026 — appears futuristic relative to the context of other sources, which stop at 2023. The technical evidence map remains independently verifiable: the token interoperability mechanisms, the panel discovery via source analysis, and the observation of post-compromise with commercial VPNs are documented with sufficient detail for technical replication.
The convergence of AiTM and device code in a single commercialized PhaaS platform represents a maturation point for the sector: the barrier to entry for less sophisticated operators drops, while defensive strategies based on URL detection or user awareness must contend with a legitimate OAuth flow that does not require direct interaction with malicious sites. Classifying the device code flow as high-risk by Microsoft — if applied — does not resolve the configuration vulnerability represented by domain-based safe sender exclusions.
The Greatness platform does not introduce new techniques to the threat landscape: device code phishing is known. What it integrates is orchestration in shared infrastructure, distributed via Telegram, with interoperable tokens and standardized templates. This evolution from kit to platform is the trend the dossier documents, and that defensive strategies must recalibrate against.
Information is based on the cited source and current as of publication.
Sources
- https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
- https://www.bleepingcomputer.com/news/security/new-greatness-service-simplifies-microsoft-365-phishing-attacks/
- https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas
- https://docs.sekoia.com/xdr/features/detect/built_in_detection_rules
- https://urlquery.net/
- https://www.halock.com/greatness-could-be-awfulness-for-microsoft-365-users/