Greatness PhaaS Evolves with Device Code Phishing for MFA Bypass
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has significantly upgraded its capabilities, now incorporating support for device code phishing. This new feature enables threat actors to bypass Multi-Factor Authentication (MFA) and gain unauthorized control over user accounts by exploiting the legitimate OAuth 2.0 Device Authorization Grant flow. The integration of device code phishing marks an escalation in PhaaS platforms, moving beyond simple credential harvesting to more sophisticated, integrated attack ecosystems, as detailed in a report shared with The Hacker News.
Understanding Greatness PhaaS and OAuth Device Code Phishing
First publicly documented by Cisco Talos in May 2023, Greatness has been observed targeting Microsoft 365 business users since mid-2022. The platform’s evolution now includes adversary-in-the-middle (AiTM) credential and token theft, OAuth consent abuse, and multi-platform targeting, encompassing services like iCloud, Yahoo, and Google Workspace. Access to Greatness is facilitated via a subscription model, with prices starting from $289 per month, offered through its public Telegram channel (@GreatnessPage), which boasts over 3,250 subscribers.
The core of the new threat lies in OAuth device code phishing. This technique abuses the OAuth 2.0 Device Authorization Grant, typically designed for input-constrained devices (e.g., smart TVs, IoT devices) to obtain an authorization code by displaying a short, user-verifiable code. Threat actors leverage this by luring victims to enter a malicious code on a legitimate service’s login page, effectively granting the attacker a token without ever needing the user’s password directly or presenting a fake login page. Trend Micro analysis notes this method is “cleaner for the attacker” as there is no need to build or maintain a fake login site; the user interacts directly with the legitimate service.
Campaign Tactics and Evasion
The Greatness PhaaS platform offers its subscribers a comprehensive operator panel featuring campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates. These templates include themes like voicemail, document sharing, QR codes, Windows Explorer, and OneDrive, simplifying the creation of convincing phishing campaigns for less technically proficient attackers. These templates provide pre-built HTML, PDF redirectors, SVGs, and letter templates, significantly lowering the barrier to entry for operators.
Recent campaigns utilizing Greatness have employed spoofed RingCentral voicemail lures. These emails demonstrate advanced evasion tactics, bypassing email gateways by leveraging safe sender exclusions. This allows phishing emails, which would otherwise fail SPF, DKIM, and DMARC checks, to land in victims’ inboxes, exploiting existing trust configurations where the target is a legitimate RingCentral customer. The emails are not merely impersonating RingCentral; they are specifically exploiting the trust that exists between a customer and their legitimate vendor.
Victims who engage with these booby-trapped links are subjected to a five-stage redirect chain. This chain incorporates anti-analysis protections, User-Agent fingerprinting, and CAPTCHA gates, ultimately directing them to either an AiTM proxy or the new device code endpoint. This intricate process is designed to maximize stealth and minimize detection. Organizations should be vigilant for detecting RingCentral voicemail phishing and similar tactics that exploit vendor trust.
Mitigation Strategies for Organizations
To counter the evolving capabilities of Greatness PhaaS and the emerging threat of device code phishing, organizations must implement a multi-layered defense strategy. Key recommendations include:
- Enhance Email Gateway Security: Strengthen email gateway configurations to identify and quarantine sophisticated phishing attempts that bypass standard SPF, DKIM, and DMARC checks, especially those exploiting safe sender lists. Implement advanced threat protection features that analyze email content and links for suspicious activity, even from seemingly legitimate senders.
- Improve Identity Verification and MFA Policies: While MFA is bypassed by device code phishing, organizations should enforce the strongest available MFA methods, ideally FIDO2-based keys, and ensure policies are configured to challenge suspicious login attempts. Monitor logs for unusual OAuth grant requests or device link activities.
- User Education and Awareness: Conduct regular training on identifying phishing attempts, particularly those involving unusual login flows or requests for device codes. Educate users about the proper use of OAuth authorization grants and to be suspicious of any unexpected requests to enter codes on seemingly legitimate sites. This is crucial for Greatness PhaaS device code phishing mitigation.
- Audit Vendor Trust Configurations: Regularly review and tighten safe sender lists and other email trust configurations, especially following any vendor breach disclosures. Treat such disclosures as triggers to audit and adjust security settings that rely on vendor trust.
- Endpoint Detection and Response (EDR): Deploy and maintain EDR solutions to detect post-compromise activity, such as token misuse or unauthorized access, even if the initial MFA bypass is successful.
The shift towards device code phishing represents a significant challenge for existing MFA implementations. Proactive defense mechanisms, combined with a well-informed user base, are essential to protect against these advanced PhaaS capabilities.
Related: ARToken PhaaS Exposes EvilTokens’ M365 Phishing Toolkit, FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts