AI Security AI安全 2h ago Updated 1h ago 更新于 1小时前 43

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens Greatness PhaaS新增设备码钓鱼功能以绕过MFA并窃取令牌

The Greatness PhaaS toolkit has added device code phishing support, exploiting the OAuth 2.0 Device Authorization Grant to bypass MFA and steal session tokens without requiring fake login pages Greatness now offers an integrated attack ecosystem supporting AiTM token theft, device code phishing, and OAuth consent abuse from a single operator panel targeting iCloud, Yahoo, and Google Workspace Subscription costs have risen from $120/month to $289/month, with over 3,250 subscribers on the public T Greatness PhaaS新增设备代码钓鱼功能,利用OAuth 2.0 Device Authorization Grant绕过MFA窃取令牌 该平台已整合AiTM代理、设备代码钓鱼和OAuth同意滥用三大攻击向量,支持iCloud/Yahoo/Google Workspace等多目标 订阅月费从120美元涨至289美元,通过Telegram频道运营,拥有3250+订阅者 攻击者利用RingCentral客户信任关系绕过邮件安全网关,即使SPF/DKIM/DMARC失败仍可投递 钓鱼链路包含五阶段重定向、反分析保护、UA指纹识别和CAPTCHA验证,降低检测风险

62
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • The Greatness PhaaS toolkit has added device code phishing support, exploiting the OAuth 2.0 Device Authorization Grant to bypass MFA and steal session tokens without requiring fake login pages
  • Greatness now offers an integrated attack ecosystem supporting AiTM token theft, device code phishing, and OAuth consent abuse from a single operator panel targeting iCloud, Yahoo, and Google Workspace
  • Subscription costs have risen from $120/month to $289/month, with over 3,250 subscribers on the public Telegram channel, indicating strong demand for accessible cybercrime tools
  • Recent campaigns use spoofed RingCentral voicemail lures that bypass email gateways by exploiting safe sender exclusions tied to legitimate vendor-customer relationships
  • Device code phishing represents a significant evolution because it uses real Microsoft login pages, eliminating visual anomalies that typically trigger user suspicion

Why It Matters

This development marks a critical escalation in PhaaS capabilities, as device code phishing removes the need for attackers to build and maintain fake login pages that can be detected and blocked by security systems. The integration of multiple attack vectors into a single platform lowers the barrier to entry for sophisticated credential theft, making advanced techniques accessible to less skilled threat actors. Organizations must reassess their MFA strategies and email security configurations, particularly around safe sender exclusions and OAuth consent monitoring.

Technical Details

  • Greatness leverages the OAuth 2.0 Device Authorization Grant flow, directing victims to a legitimate Microsoft device code page where they enter a short code and their password, allowing attackers to silently obtain tokens without user interaction on a phishing site
  • The platform implements a five-stage redirect chain with anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before routing victims to either an AiTM proxy or the new device code endpoint
  • Phishing lures include over 11 downloadable templates (AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer) packaged with pre-built HTML, PDF redirectors, SVGs, and letter templates
  • Stolen cookies are protected via one-way hash encryption, accessible only through the customer's Telegram account with 2FA, with operator-specific domains provisioned in the format "api-[token].[base-domain]"
  • Recent campaigns exploit vendor breach disclosures by targeting organizations that have legitimate RingCentral customers, using safe sender exclusions to bypass SPF, DKIM, and DMARC checks

Industry Insight

  • Security teams should treat vendor breach disclosures as immediate triggers to audit and tighten email safe sender exclusion rules, as exposed customer lists enable highly targeted phishing that bypasses traditional email gateway protections
  • Organizations should implement OAuth consent monitoring and alerting to detect unauthorized application permissions being granted through consent abuse attacks, which complement device code phishing in Greatness's toolkit
  • The rapid evolution from AiTM to device code phishing demonstrates that MFA alone is insufficient; defenders should advocate for phishing-resistant authentication methods such as FIDO2/WebAuthn hardware keys or certificate-based authentication to mitigate these token theft techniques

TL;DR

  • Greatness PhaaS新增设备代码钓鱼功能,利用OAuth 2.0 Device Authorization Grant绕过MFA窃取令牌
  • 该平台已整合AiTM代理、设备代码钓鱼和OAuth同意滥用三大攻击向量,支持iCloud/Yahoo/Google Workspace等多目标
  • 订阅月费从120美元涨至289美元,通过Telegram频道运营,拥有3250+订阅者
  • 攻击者利用RingCentral客户信任关系绕过邮件安全网关,即使SPF/DKIM/DMARC失败仍可投递
  • 钓鱼链路包含五阶段重定向、反分析保护、UA指纹识别和CAPTCHA验证,降低检测风险

为什么值得看

本文揭示了PhaaS工具从单一凭证窃取向集成化攻击生态演进的典型路径,设备代码钓鱼利用合法OAuth流程绕过MFA的技术细节对安全防御具有直接参考价值。攻击者利用供应商信任关系绕过邮件网关的新手法,为组织邮件安全策略提供了重要的威胁情报。

技术解析

  • OAuth设备授权滥用:攻击者利用OAuth 2.0 Device Authorization Grant(RFC 8628)流程,通过生成设备验证码引导用户在合法Microsoft页面输入密码,实现无交互令牌窃取,规避传统钓鱼网站检测
  • 五阶段反分析链路:钓鱼链接经过五层重定向,集成User-Agent指纹识别、CAPTCHA验证和反沙箱机制,仅对真实用户流量开放最终攻击页面
  • 多向量攻击架构:单一控制面板支持AiTM实时代理、设备代码钓鱼和OAuth同意滥用,共享后端基础设施实现攻击流程自动化
  • 邮件投递优化:针对RingCentral客户群体,利用其安全发件人白名单配置绕过邮件网关,即使邮件认证失败仍可投递至收件箱
  • 数据保护机制:声称采用单向哈希保护窃取Cookie,仅通过Telegram 2FA验证的账户可访问日志数据

行业启示

  • MFA防御升级:设备代码钓鱼暴露了传统MFA在OAuth流程中的盲区,需推动基于风险的身份验证和异常设备行为检测
  • 供应商信任管理:企业应定期审计安全发件人白名单,将供应商数据泄露事件纳入邮件策略调整触发条件
  • PhaaS生态监控:关注Telegram等暗网渠道的定价变化和模板更新,设备代码钓鱼模板可能快速扩散至其他犯罪工具

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全