A new phishing-as-a-service called Greatness has been used by cybercriminals to target business users of the Microsoft 365 cloud service since at least mid-2022, Cisco Talos reports.

Greatness consists of a decoy and link builder that creates highly convincing decoy and login pages.

It also has features such as having the victim’s email address pre-filled and displaying their appropriate company logo and background image.

Each affiliate will need to have a valid API key in order to be able to load the phishing page.

The API key also prevents unwanted IP addresses from viewing the Phishing page and facilitates behind-the-scenes communication with the actual Microsoft 365 login page by posing as the victim.

