RingCentral Spoof Hijacks M365 Accounts
Phishing service Greatness uses spoofed RingCentral emails to bypass MFA and compromise Microsoft 365 accounts.
A corporate phishing platform has expanded its operations to breach multi-factor authentication defenses across enterprise Microsoft 365 deployments. According to research published by cybersecurity firm ZeroBEC, threat actors are deploying spoofed RingCentral communications designed to siphon valid session tokens directly from victim organizations.
Fake Notifications Direct Victims to Attack Infrastructure
The attack sequence relies on targeted email messages crafted to impersonate genuine administrative communications from business communications provider RingCentral. Researchers at ZeroBEC reported that targets receive deceptive notices, specifically framed as standard fake voicemail alerts or performance-review notifications.
Despite their legitimate appearance to end users, technical analysis reveals these messages originate from unrecognized mail servers. The incoming phishing emails consistently fail both Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting, and Conformance (DMARC) validation checks.
When recipients click the embedded links within these alerts, they are redirected away from corporate channels onto attacker-controlled infrastructure hosting a spoofed Microsoft 365 login page designed to mimic official authentication portals.
Token Theft Mechanism Bypasses Authentication Controls
The malicious landing page operates as an intermediary interface through the Greatness phishing-as-a-service platform. Rather than solely harvesting static credentials, the service captures active MFA-approved authentication tokens during the user's logon session.
By capturing these session tokens in real time, the operators behind Greatness effectively circumvent secondary security verification measures without needing to manipulate or break the underlying multi-factor protocol itself. Once the valid token is acquired, attackers obtain direct entrance to target enterprise accounts.
Data Enumeration Across Microsoft Graph Infrastructure
After acquiring valid session tokens, adversaries systematically search compromised environments for sensitive operational data. Researchers report that Greatness operators routinely enumerate email mailboxes within Outlook, active corporate messaging threads inside Teams, and shared enterprise documentation hosted on SharePoint sites.
The intrusions further extend into cloud file repositories and organizational directory structures. Through the programmatic query capabilities of Microsoft Graph, attackers extract OneDrive files, employee contact directories, calendar schedules, and administrative records linked to registered applications within the targeted tenant.
Potential Link to Previous Breach at RingCentral
Security analysts at ZeroBEC noted that the choice of spoofing target coincides with a prior security incident affecting RingCentral. Cybercriminal group ShinyHunters previously conducted a data breach against RingCentral, creating the possibility that stolen customer records contributed to the current phishing activity.
Researchers observe that while an explicit link remains unconfirmed, threat actors likely exfiltrated a directory of RingCentral customer email addresses during that breach. This victim list provides attackers with a tailored recipient pool, increasing the plausibility of their impersonation campaigns.
Four Years of Targeted International Operations
While the focus on RingCentral impersonation represents a specific tactic, the underlying Greatness PhaaS service maintains a longer operational history. According to ZeroBEC, the platform has actively sustained operations for at least four years across multiple geographic markets.
Although the platform originally functioned as a conventional credential-harvesting service, it has since evolved to target accounts across iCloud, Yahoo, and Google Workspace in addition to Microsoft 365 environments. Campaign activity has specifically impacted organization targets located across five primary regions:
- US enterprise and organizational account holders
- UK commercial and public sector endpoints
- Australia business environments and user accounts
- Canada corporate and institutional targets
- South Africa network infrastructure and user profiles
Commercial Availability Across Underground Channels
The infrastructure powering these attacks is distributed widely across illicit criminal marketplaces. As reported by BleepingComputer, the Greatness service is actively marketed to potential buyers through Telegram channels that hold subscriber counts in the thousands.
Access to the platform's toolset and hosting capabilities is sold under a subscription model. The service is currently offered to purchasers for a recurring monthly fee of $289, lowering the technical barrier to entry for conducting token-stealing phishing campaigns.
Enterprise Consequences and Risk Mitigation
The continuous evolution of phishing-as-a-service toolkits indicates that traditional perimeter defenses and password-based controls offer diminished protection when session tokens can be intercepted externally. Because these attacks bypass standard multi-factor prompts by proxying active logins, organizations relying solely on basic MFA configurations face heightened risk of post-authentication exposure.
Defenders managing enterprise cloud infrastructure may need to evaluate strict email validation policies—including automatic dropping of messages failing SPF and DMARC—while implementing token protection controls and monitoring Microsoft Graph API queries for unusual data harvesting activity.
Sources
- TechRadar Original source
- BleepingComputer Also reporting
Continue Reading
Fake Bank Alerts Facilitate RMM Access
Researchers identify a sophisticated phishing campaign using brand impersonation to deploy remote access malware on Windows.
Open VSX Marketplace Faced 77 Impostors
A malicious campaign on the Open VSX marketplace deployed 77 counterfeit extensions to harvest developer metadata.
Roblox Cheat Tool Spreads Hidden Malware
A malicious version of the Xeno Executor mod is infecting computers with a RAT, granting attackers full control over user devices.