Gloriousness has surfaced as a phishing-as-a-service platform aimed at stealing Microsoft 365 access during times when organizations mistakenly believe multi-factor authentication will prevent account takeover attempts.

Indicators of Compromise (IoCs): Type Indicator Description Domain searchbriefing.com Initial click-tracking redirect Domain loading.finreportviewersoftware.sbs Anti-analysis redirector Domain api-8g9ezadxs.onewayoutlook.one Operator API endpoint Domain onewayoutolook.one Greatness phishing domain Domain xdccoc.top AiTM credential-theft domain Domain nawarra.top AiTM phishing domain Domain saileventpartners.top AiTM phishing domain Domain greatwallwebsite.blog Greatness backend panel API Domain hashmiaghayi.cfd Operator-provisioned phishing domain Domain addtoitinnew.sbs Phishing domain exposed in panel Domain willgrantitinfewsecondafter.cfd Phishing domain exposed in panel Domain lookatemailplease.one Phishing domain exposed in panel Domain pleasebepatienttoload.sbs Phishing domain exposed in panel Domain landfomarkpool.nl Device-code phishing landing page Domain 638uneconomical.birchibase.co.nl Device-code phishing redirector IP address 212.227.146.181 IONOS email origin used for spoofed sender activity IP address 38.248.95.214 Common AiTM proxy and post-compromise login infrastructure IP address 38.248.95.228 Candidate monitoring host with matching infrastructure fingerprint IP address 38.248.95.236 Candidate monitoring host with matching infrastructure fingerprint IP address 158.173.166.3 Post-compromise login and token-replay activity IP address 46.173.240.225 Post-compromise VPN exit node IP address 46.173.240.21 Post-compromise VPN exit node IP address 46.173.240.190 Post-compromise VPN exit node IP address 46.173.240.180 Post-compromise VPN exit node IP address 46.173.240.127 Post-compromise VPN exit node IP address 46.173.240.118 Post-compromise VPN exit node IP address 46.173.240.17 Post-compromise VPN exit node Email address serviceringcentral.com Spoofed sender address Operator token 8g9ezadxs Campaign token associated with redirector activity Operator token 4am16l1tm Campaign token tied to nawarra.top and saileventpartners.top Cookie name laravelsession Laravel session cookie observed on suspicious infrastructure Cookie name XSRF-TOKEN Laravel anti-forgery cookie observed on suspicious infrastructure Web-page title just a moment Misspelled redirector title used as a hunting fingerprint URL path rgateclus Redirector routing-path pattern Subdomain pattern api-[9-character-token].domain Greatness operator API domain convention Display name pattern Your target-domain.com Performance Check Spoofed email display-name pattern Subject pattern Action required: Review your performance appraisal Observed urgency-themed phishing subject Subject pattern URGENT: Your Performance Review is Ready Observed urgency-themed...