Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Summary

The Greatness phishing-as-a-service (PhaaS) platform has evolved to include adversary-in-the-middle and device-code phishing techniques, specifically targeting Microsoft 365 accounts. This expansion leverages legitimate RingCentral services to spoof login pages, making it harder for users to detect fraudulent requests.

IFF Assessment

FOE

This article details the evolution of a phishing-as-a-service platform that now uses more sophisticated techniques to steal credentials, posing a significant threat to defenders.

Defender Context

Defenders should be aware of advanced phishing techniques like adversary-in-the-middle and device-code phishing, especially those targeting widely used services like Microsoft 365. User education on recognizing spoofed legitimate services and the importance of multi-factor authentication (MFA) is crucial, as these attacks aim to bypass standard security measures.

Read Full Story →