Cisco Talos researcher, Tiago Pereira, has warned of the dangers of a new phishing-as-a-service (PaaS) tool called “Greatness.” The Greatness tool has been designed to compromise Microsoft 365 users and can make phishing pages especially convincing and effective against businesses. Greatness incorporates many advanced features including multi-factor authentication (MFA) bypass, IP filtering and integration with Telegram bots.
Since the attack starts with a malicious email, the advice is to implement robust email security solutions that include spam filters, antivirus software, firewalls plus keep antivirus and other software updates and patches up to date, not to open any unsolicited and/or suspicious emails, and to make sure there is employee education and awareness regarding spotting, reporting, and dealing with phishing attacks.