Skip to main content
[TIMESTAMP: 2026-08-04 17:30 UTC] [AUTHOR: Runtime Rebel Intel] [SEVERITY: HIGH]

Greatness PhaaS Adds Device Code Phishing for MFA Bypass

AI-generated analysis
READ_TIME: 5 min read
Primary source: thehackernews.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

// executive briefing tl;dr
  • [01] Immediate impact: Greatness PhaaS enables threat actors to bypass MFA and seize control of user accounts through device code phishing.
  • [02] Affected systems: Users of Microsoft 365, Google Workspace, iCloud, and Yahoo are primary targets for account takeover.
  • [03] Remediation: Enhance email gateway defenses, implement stronger identity verification, and train users on OAuth authorization flows.

Advertisement

Greatness PhaaS Evolves with Device Code Phishing for MFA Bypass

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has significantly upgraded its capabilities, now incorporating support for device code phishing. This new feature enables threat actors to bypass Multi-Factor Authentication (MFA) and gain unauthorized control over user accounts by exploiting the legitimate OAuth 2.0 Device Authorization Grant flow. The integration of device code phishing marks an escalation in PhaaS platforms, moving beyond simple credential harvesting to more sophisticated, integrated attack ecosystems, as detailed in a report shared with The Hacker News.

Understanding Greatness PhaaS and OAuth Device Code Phishing

First publicly documented by Cisco Talos in May 2023, Greatness has been observed targeting Microsoft 365 business users since mid-2022. The platform’s evolution now includes adversary-in-the-middle (AiTM) credential and token theft, OAuth consent abuse, and multi-platform targeting, encompassing services like iCloud, Yahoo, and Google Workspace. Access to Greatness is facilitated via a subscription model, with prices starting from $289 per month, offered through its public Telegram channel (@GreatnessPage), which boasts over 3,250 subscribers.

The core of the new threat lies in OAuth device code phishing. This technique abuses the OAuth 2.0 Device Authorization Grant, typically designed for input-constrained devices (e.g., smart TVs, IoT devices) to obtain an authorization code by displaying a short, user-verifiable code. Threat actors leverage this by luring victims to enter a malicious code on a legitimate service’s login page, effectively granting the attacker a token without ever needing the user’s password directly or presenting a fake login page. Trend Micro analysis notes this method is “cleaner for the attacker” as there is no need to build or maintain a fake login site; the user interacts directly with the legitimate service.

Campaign Tactics and Evasion

The Greatness PhaaS platform offers its subscribers a comprehensive operator panel featuring campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates. These templates include themes like voicemail, document sharing, QR codes, Windows Explorer, and OneDrive, simplifying the creation of convincing phishing campaigns for less technically proficient attackers. These templates provide pre-built HTML, PDF redirectors, SVGs, and letter templates, significantly lowering the barrier to entry for operators.

Recent campaigns utilizing Greatness have employed spoofed RingCentral voicemail lures. These emails demonstrate advanced evasion tactics, bypassing email gateways by leveraging safe sender exclusions. This allows phishing emails, which would otherwise fail SPF, DKIM, and DMARC checks, to land in victims’ inboxes, exploiting existing trust configurations where the target is a legitimate RingCentral customer. The emails are not merely impersonating RingCentral; they are specifically exploiting the trust that exists between a customer and their legitimate vendor.

Victims who engage with these booby-trapped links are subjected to a five-stage redirect chain. This chain incorporates anti-analysis protections, User-Agent fingerprinting, and CAPTCHA gates, ultimately directing them to either an AiTM proxy or the new device code endpoint. This intricate process is designed to maximize stealth and minimize detection. Organizations should be vigilant for detecting RingCentral voicemail phishing and similar tactics that exploit vendor trust.

Mitigation Strategies for Organizations

To counter the evolving capabilities of Greatness PhaaS and the emerging threat of device code phishing, organizations must implement a multi-layered defense strategy. Key recommendations include:

  • Enhance Email Gateway Security: Strengthen email gateway configurations to identify and quarantine sophisticated phishing attempts that bypass standard SPF, DKIM, and DMARC checks, especially those exploiting safe sender lists. Implement advanced threat protection features that analyze email content and links for suspicious activity, even from seemingly legitimate senders.
  • Improve Identity Verification and MFA Policies: While MFA is bypassed by device code phishing, organizations should enforce the strongest available MFA methods, ideally FIDO2-based keys, and ensure policies are configured to challenge suspicious login attempts. Monitor logs for unusual OAuth grant requests or device link activities.
  • User Education and Awareness: Conduct regular training on identifying phishing attempts, particularly those involving unusual login flows or requests for device codes. Educate users about the proper use of OAuth authorization grants and to be suspicious of any unexpected requests to enter codes on seemingly legitimate sites. This is crucial for Greatness PhaaS device code phishing mitigation.
  • Audit Vendor Trust Configurations: Regularly review and tighten safe sender lists and other email trust configurations, especially following any vendor breach disclosures. Treat such disclosures as triggers to audit and adjust security settings that rely on vendor trust.
  • Endpoint Detection and Response (EDR): Deploy and maintain EDR solutions to detect post-compromise activity, such as token misuse or unauthorized access, even if the initial MFA bypass is successful.

The shift towards device code phishing represents a significant challenge for existing MFA implementations. Proactive defense mechanisms, combined with a well-informed user base, are essential to protect against these advanced PhaaS capabilities.

Related: ARToken PhaaS Exposes EvilTokens’ M365 Phishing Toolkit, FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts

Advertisement

Advertisement