No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

New phishing-as-a-service tool targeting Microsoft 365 users

May 13, 2023
in Protection
0
New phishing-as-a-service tool targeting Microsoft 365 users


A new phishing-as-a-service called “Greatness” has been offering affiliates an attachment and link builder to make convincing Microsoft 365 decoy and login pages, making it well-suited to target business users.

Researchers at Cisco Talos noted in a May 10 blog that several phishing campaigns using the service have been observed since at least mid-2022, with spikes in activity in December and March. The campaigns have been targeting mostly manufacturing, healthcare and technology companies in the U.S., UK, South Africa and Canada, with over 50% of all targets based in the U.S. alone.

Researcher Tiago Pereira wrote that “affiliates must deploy and configure a provided phishing kit with an API key that allows even unskilled threat actors to easily take advantage of the service’s more advanced features. The phishing kit and API work as a proxy to the Microsoft 365 authentication system, performing a ‘man-in-the-middle’ attack and stealing the victim’s authentication credentials or cookies.”

Pererira explained that the phishing-as-a-service contains a phishing kit (which contains the admin panel), the service API and a Telegram bot or email address.

The attack begins when victims receive a malicious email that typically has an HTML file attachment, Pererira continued. Opening the attachment runs an obfuscated JavaScript code in the web browser that contains a blurred image displaying a spinning wheel to pretend it’s loading a document.

A blurred document decoy attachment is seen by victims of a new phishing-as-a-service attack. (image via Cisco Talos)

The victim is then redirected to a Microsoft 365 login page that’s often pre-filled with their email address and a custom background and logo used by their company. Once the victim types in their password, the phishing service connects to Microsoft 365 and impersonates the victim to attempt a log in. The phishing-as-a-service will even prompt the victim to authenticate a multi-factor authentication request by the real Microsoft 365 page, such as SMS code or push notification.

The PaaS kit stores the credentials locally so they can be accessed via the administrative panel and sends them to the affiliate’s Telegram channel, if configured to do so. 

As Pererira wrote: “Working together, the phishing kit and the API perform a ‘man-in-the-middle’ attack, requesting information from the victim that the API will then submit to the legitimate login page in real time.” Since authentication sessions time out after a while, the attacker is informed as soon as possible by the Telegram bot that the victim’s authenticated session cookies have been obtained.

Editorial Team

Editorial Team

Related Posts

The Best Budget Treadmill Is Even Cheaper During Amazon's Big Spring Sale
Protection

The Best Budget Treadmill Is Even Cheaper During Amazon’s Big Spring Sale

March 25, 2026
These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale
Protection

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale

March 25, 2026
The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale
Protection

The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale

March 25, 2026
Follow the Best Deals From Amazon's Big Spring Sale in Real Time
Protection

Follow the Best Deals From Amazon’s Big Spring Sale in Real Time

March 25, 2026
This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale
Protection

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale

March 25, 2026
The DJI Osmo 360 Essential Combo Is Over $200 Off for Amazon's Spring Sale
Protection

The DJI Osmo 360 Essential Combo Is Over $200 Off for Amazon’s Spring Sale

March 25, 2026
Load More
Next Post
Soros Slashed Rivian Stake After 90% Drop From Peak, Exits Tesla

Soros Slashed Rivian Stake After 90% Drop From Peak, Exits Tesla

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • Majority of Fitch-rated sub lines have AA+ rating

    0 shares
    Share 0 Tweet 0

Latest News

Single women first-time homebuyers' income beats solo men

Single women first-time homebuyers’ income beats solo men

March 25, 2026
0

Toucanstudios | E+ | Getty ImagesSingle women have long outpaced single men as homebuyers — and they may be pulling...

XRP Realizes Its Quietest Month Of 2026 – Traders Watch for What Comes Next

XRP Realizes Its Quietest Month Of 2026 – Traders Watch for What Comes Next

March 25, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure XRP is consolidating around $1.43. The market...

Yeti Promo Codes and Deals: Save 20% on Gear

Yeti Promo Codes and Deals: Save 20% on Gear

March 25, 2026
0

Spring has finally arrived, and what better way to kick off the season than by going camping, hiking, or outdoor...

SpaceX reportedly could file for an IPO this week. These funds allow you to invest right now

SpaceX reportedly could file for an IPO this week. These funds allow you to invest right now

March 25, 2026
0

As SpaceX potentially readies to begin the progress of going public in the coming days, investors already have funds to...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.