https://bit.ly/44PD7VE - 🔒 A new Phishing-as-a-Service (PhaaS) platform, 'Greatness', is targeting organizations using Microsoft 365 in countries like the US, Canada, UK, Australia, and South Africa. The Greatness phishing platform, which launched in 2022, has seen a surge in activity since December 2022 and March 2023. The majority of victims work in sectors like manufacturing, healthcare, technology, education, real estate, construction, finance, and business services. #CyberSecurity #Phishing 💻 'Greatness' provides a comprehensive solution for phishing campaigns. The process begins with the user entering target email addresses on the 'Greatness' admin panel. The PhaaS platform then sets up the necessary infrastructure, such as the server hosting the phishing page and generating the HTML attachment. The user crafts the email content, makes any necessary changes, and then the service emails the victims. #CyberCrime #GreatnessPhishing 🔗 Victims receive a phishing email with an HTML attachment. Upon opening the attachment, JavaScript code connects with the 'Greatness' server, fetching a convincing phishing page featuring the victim's company logo and background from the actual Microsoft 365 login page. The user is tricked into entering their password, with 'Greatness' pre-filling the correct email for a sense of legitimacy. #PhishingAttack #DataSecurity 🛡️ 'Greatness' acts as a proxy between the victim's browser and the Microsoft 365 login page, obtaining a valid session cookie for the target account. If the account has two-factor authentication, the victim is prompted to provide it. Once the MFA code is provided, 'Greatness' authenticates as the victim on the actual Microsoft platform and sends the authenticated session cookie to the affiliate via Telegram or on the service's web panel. #TwoFactorAuthentication #CyberThreats 🎯 Attackers then use the session cookie to access the victim's email, files, and data in Microsoft 365 services. The stolen credentials are also leveraged for more dangerous attacks, like breaching corporate networks and deploying ransomware. Stay vigilant, protect your data, and remember to always confirm the legitimacy of an email before providing your credentials.