The Greatness tool, an example of commercial phishing-as-a-service (PhaaS), has expanded its capabilities by incorporating device code phishing as part of a growing cyber threat This article explores phishing service phaas. . This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems.
Designed as a way to lower the barrier of entry for cybercrime, access to Greatness is facilitated through a subscription available on its public-facing Telegram channel (@GreatnessPage) with over 3,250 subscribers and serves as a central hub for announcements and feature updates.
"Each template features pre-built HTML, PDF redirectors, SVGs, and letter templates, reducing the need for operators to start from scratch." Victims who come across a booby-trapped link in phishing emails go through a five-stage redirect chain with anti-analysis protections, User-Agent fingerprinting, and CAPTCHA gates before reaching their final destination. This makes it particularly deceptive because it mimics legitimate behavior without raising suspicion."
Recent campaigns using the PhaaS kit have employed spoofed RingCentral voicemail lures to bypass email gateways through safe sender exclusions, landing on victims' inboxes despite failing SPF, DKIM, and DMARC checks.
ZeroBEC has observed one of AiTM proxy IP addresses ("38.248.95[. ]214") actively authenticating against a victim's Microsoft 365 account more than two weeks after the initial phishing campaign, indicating how prolonged token validity can allow attackers continued access for extended periods.












