No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Plug-and-Play Microsoft 365 Phishing Tool ‘Democratizes’ Attack Campaigns

May 12, 2023
in Protection
0
Plug-and-Play Microsoft 365 Phishing Tool 'Democratizes' Attack Campaigns



A previously unreported phishing-as-a-service (PaaS) tool allows even script kiddies to build compelling, effective phishing attacks against businesses.

Researchers at Cisco Talos detailed their findings on “Greatness,” a one-stop-shop for all of a cybercriminal’s phishing needs. With Greatness, anyone with even rudimentary technical chops can craft compelling Microsoft 365-based phishing lures, then carry out man-in-the-middle attacks that steal authentication credentials — even in the face of multifactor authentication (MFA) — and much more.

The tool has been in circulation since at least mid-2022 and has been used in attacks against enterprises in manufacturing, healthcare, and technology, among other sectors. Half of the targets thus far have been concentrated in the US, with further attacks occurring around Western Europe, Australia, Brazil, Canada, and South Africa.

“It’s designed to be accessible,” says Nick Biasini, head of outreach for Cisco Talos. “It democratizes access to phishing campaigns.”

How Greatness Works

To a victim, Greatness will come in the form of an email with a link, or usually an attachment disguising an HTML page. Clicking on the attachment will open a blurred image of a Microsoft document behind a loading wheel, giving the impression that the file is loading. But the document never loads. Instead, the victim is redirected to a Microsoft 365 login page.

That might seem suspicious if not for the fact that the victim’s email address, as well as their company’s logo, are already pre-filled on the page, lending an air of legitimacy to the whole affair.

At this point, the man-in-the-middle scheme begins. The victim submits their password to 365, not knowing they’re helping to log in their own attacker. Even if a victim has MFA implemented, it’s no problem. 365 requests a code, the victim submits it, Greatness intercepts it, and the ruse continues. Greatness collects its authenticated session cookies and passes it on to the threat actor via Telegram or its admin panel.

It used to take time, effort, and coding to craft phishing attacks this convincing. With Greatness, all you have to do is fill out a form: title, caption, an image of an Excel spreadsheet to trick them with, and so on. Enabling the “autograb” feature automatically pre-fills the 365 login page with the victim’s email address, according to Talos’ findings.

“Basically you just pay, you get access to your API, and that’s it,” Biasani says. “You have to understand some basic things, like what API keys are, and how to apply it in the portal, but it’s pretty, pretty user-friendly.”

Why Greatness Works So Great

Because Greatness is so slick in presentation and so effortlessly bypasses MFA, simple awareness and cyber hygiene may not be enough to save an enterprise from its grasp.

One simple change organizations can make is to adjust cookie session timeouts. “Having a timeout value of, like, two weeks is not a good look in the threat landscape that we’re looking at today,” Biasani explains. He adds, though, that “the challenge is you also have a user base, and forcing people to use MFA every five minutes is not going to go over very well, either. So you’re kind of sitting in that middle space: a security decision versus a usability decision. It’s a very tough balance.”

Where simple fixes won’t solve the problem, more sophisticated security is required. “This is where you start getting into things like anomaly detection,” he notes, “and location-based logins. Things like that. You’re going to have to take your detection up a level.”

Still, Biasani sees a silver lining. “To me, more than anything else, it shows that MFA actually works … because they’re [attackers] really actively trying to do something to counter it now,” he says. “MFA is hitting a point where they can’t ignore it anymore.”

Editorial Team

Editorial Team

Related Posts

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale
Protection

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

March 25, 2026
Spotify's New 'SongDNA' Is Actually a Great Way to Learn More About Your Music
Protection

Spotify’s New ‘SongDNA’ Is Actually a Great Way to Learn More About Your Music

March 25, 2026
The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor
Protection

The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor

March 25, 2026
Ultrahuman’s New Ring Pro Is Finally Available in the US
Protection

Ultrahuman’s New Ring Pro Is Finally Available in the US

March 25, 2026
10 Shows Like 'Call the Midwife' You Should Watch Next
Protection

10 Shows Like ‘Call the Midwife’ You Should Watch Next

March 25, 2026
What The FCC's Router Ban Could Mean for You
Protection

What The FCC’s Router Ban Could Mean for You

March 25, 2026
Load More
Next Post
Bitcoin, Ether fall to month lows; Polygon leads losers; U.S. equity futures up as inflation cools

Bitcoin, Ether fall to month lows; Polygon leads losers; U.S. equity futures up as inflation cools

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Time4Advice founders to retire as Richard Brian steps into leadership role

    0 shares
    Share 0 Tweet 0
  • Majority of Fitch-rated sub lines have AA+ rating

    0 shares
    Share 0 Tweet 0

Latest News

Merck makes a big move into new cancer treatments with a $6.7 billion buyout deal

Merck makes a big move into new cancer treatments with a $6.7 billion buyout deal

March 25, 2026
0

Merck to spend $6.7 billion to buy Terns Pharmaceuticals, which is developing an oral treatment for leukemia.

XRP price crypto analyst

XRP Pundit Shares Why You Shouldn’t Get Tricked By The Price Rebound

March 25, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Recently, the XRP price has been in...

Arrow Global launches specialty insurance arm

Arrow Global launches specialty insurance arm

March 25, 2026
0

European alternatives manager Arrow Global has launched an insurance arm focused on the specialty market, diverging from the broader trend...

Bhutan Moves 519 Bitcoin as Sovereign Wallet Drawdown Continues

Bhutan Moves 519 Bitcoin as Sovereign Wallet Drawdown Continues

March 25, 2026
0

Bhutan moved more Bitcoin from its state-linked wallet on Wednesday, extending a March drawdown in its sovereign holdings.Arkham data showed...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.