Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness PhaaS toolkit has added device code phishing support, exploiting the OAuth 2.0 Device Authorization Grant to bypass MFA and steal session tokens without requiring fake login pages Greatness now offers an integrated attack ecosystem supporting AiTM token theft, device code phishing, and OAuth consent abuse from a single operator panel targeting iCloud, Yahoo, and Google Workspace Subscription costs have risen from $120/month to $289/month, with over 3,250 subscribers on the public T
Analysis
TL;DR
- The Greatness PhaaS toolkit has added device code phishing support, exploiting the OAuth 2.0 Device Authorization Grant to bypass MFA and steal session tokens without requiring fake login pages
- Greatness now offers an integrated attack ecosystem supporting AiTM token theft, device code phishing, and OAuth consent abuse from a single operator panel targeting iCloud, Yahoo, and Google Workspace
- Subscription costs have risen from $120/month to $289/month, with over 3,250 subscribers on the public Telegram channel, indicating strong demand for accessible cybercrime tools
- Recent campaigns use spoofed RingCentral voicemail lures that bypass email gateways by exploiting safe sender exclusions tied to legitimate vendor-customer relationships
- Device code phishing represents a significant evolution because it uses real Microsoft login pages, eliminating visual anomalies that typically trigger user suspicion
Why It Matters
This development marks a critical escalation in PhaaS capabilities, as device code phishing removes the need for attackers to build and maintain fake login pages that can be detected and blocked by security systems. The integration of multiple attack vectors into a single platform lowers the barrier to entry for sophisticated credential theft, making advanced techniques accessible to less skilled threat actors. Organizations must reassess their MFA strategies and email security configurations, particularly around safe sender exclusions and OAuth consent monitoring.
Technical Details
- Greatness leverages the OAuth 2.0 Device Authorization Grant flow, directing victims to a legitimate Microsoft device code page where they enter a short code and their password, allowing attackers to silently obtain tokens without user interaction on a phishing site
- The platform implements a five-stage redirect chain with anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before routing victims to either an AiTM proxy or the new device code endpoint
- Phishing lures include over 11 downloadable templates (AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer) packaged with pre-built HTML, PDF redirectors, SVGs, and letter templates
- Stolen cookies are protected via one-way hash encryption, accessible only through the customer's Telegram account with 2FA, with operator-specific domains provisioned in the format "api-[token].[base-domain]"
- Recent campaigns exploit vendor breach disclosures by targeting organizations that have legitimate RingCentral customers, using safe sender exclusions to bypass SPF, DKIM, and DMARC checks
Industry Insight
- Security teams should treat vendor breach disclosures as immediate triggers to audit and tighten email safe sender exclusion rules, as exposed customer lists enable highly targeted phishing that bypasses traditional email gateway protections
- Organizations should implement OAuth consent monitoring and alerting to detect unauthorized application permissions being granted through consent abuse attacks, which complement device code phishing in Greatness's toolkit
- The rapid evolution from AiTM to device code phishing demonstrates that MFA alone is insufficient; defenders should advocate for phishing-resistant authentication methods such as FIDO2/WebAuthn hardware keys or certificate-based authentication to mitigate these token theft techniques
Disclaimer: The above content is generated by AI and is for reference only.