{"id":2204,"date":"2026-08-04T18:04:33","date_gmt":"2026-08-04T18:04:33","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2204"},"modified":"2026-08-04T18:04:33","modified_gmt":"2026-08-04T18:04:33","slug":"greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2204","title":{"rendered":"Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi8YRyOCSodUbPpWMicgOiuGbEQWDBmu_W-47PAUFkS7yKEQe4Do6svH4cQb-U0tC53C9mqq8ijjlG9gwuzyqYfNwtS61WxvNxIgk1dVC7wX598rncb_MgQ5t4yxc8NUYVdb6PT5cu7ZXJ7w3KaYG_7vtU5xixHel1jSADbtR-GC1bmngZPArXw-NjkTH1x\/s1700-e365\/Greatness.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The commercial phishing-as-a-service (PhaaS) toolkit known as <strong>Greatness<\/strong> has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.<\/p>\n<p>\u00abGreatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure,\u00bb ZeroBEC <a href=\"https:\/\/zerobec.com\/blog\/greatness-phaas-aitm-and-device-code-phishing\" target=\"_blank\">said<\/a> in a report shared with The Hacker News detailing the PhaaS kit&#8217;s latest capabilities.<\/p>\n<p>\u00abThe platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems.\u00bb<\/p>\n<p>The phishing platform was first publicly documented by Cisco Talos in May 2023, highlighting how threat actors are incorporating it in their attacks to target Microsoft 365 business users since at least mid-2022.<\/p>\n<p>Designed as a way to lower the barrier of entry for cybercrime, access to Greatness is facilitated through a subscription available on its public-facing Telegram channel (@GreatnessPage) that has more than 3,250 subscribers and serves as a central hub for announcements and feature updates.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Aspiring cybercriminals can obtain a subscription starting from $289 per month, up from the $120 per month figure reported back in January 2024. The subscription provides access to an operator that includes a dashboard with campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates covering voicemail, document sharing, and QR codes, among others.<\/p>\n<p>Operator registration, license provisioning, and support are offered via a dedicated Telegram bot (@gr8managerbot), while licenses can be procured or renewed by sending a message to the \u00ab@greatnessmgr\u00bb account, the developer handle that oversees operator support and platform development.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>In a <a href=\"https:\/\/t.me\/GreatnessPage\/125\" target=\"_blank\">post<\/a> shared in November 2025, the operators of the Telegram channel claim that Greatness keeps stolen cookies safe and secure via one-way hash protection and that the information can be extracted only by the customers with their Telegram account 2FA code.<\/p>\n<p><em>When you logged in with your telegram account and you insert 2FA in your side will create a token that only can access your logs so be sure only person can access is you as you see all info is hashed. Only way is accessing your telegram account so keep it safe and everything will be fine!<\/em><\/p>\n<p><em>The most important thing for any service user is privacy. We respect all users&#8217; privacy because we have been in this business for 8 years and prioritize everything to provide you the best experience. Unlike others, we are always honest with our customers.<\/em><\/p>\n<p>Those who purchase a subscription by providing their Telegram chat ID and a bot API token can access the panel through a login page that requires a user ID and a 9-character license key to access the dashboard. Upon successful registration, customers are provisioned an operator-specific domain in the format: \u00abapi-[token].[base-domain].\u00bb<\/p>\n<p>The dashboard is a one-stop shop that offers comprehensive campaign statistics, including the cookies captured and a heat map of victims. It also includes a links configuration page to select their phishing domain, CAPTCHA type, background theme, and the method for saving cookies, while the attachments section provides more than 11 downloadable and ready-to-use phishing lure templates that are packaged as ZIP files.<\/p>\n<p>\u00abObserved templates include: AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer, and additional variants,\u00bb ZeroBEC said. \u00abEach template contains pre-built HTML, PDF redirectors, SVGs, and letter templates, lowering the barrier to entry so operators do not need to build lures from scratch.\u00bb<\/p>\n<p>Victims who end up interacting with a booby-trapped link embedded in the phishing email traverse through a five-stage redirect chain that implements anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate, before taking them to the final destination, which can be either an AitM proxy or a device code endpoint.<\/p>\n<p>The <a href=\"https:\/\/blog.barracuda.com\/2026\/04\/16\/threat-spotlight-tycoon-2fa-scattered-everywhere\" target=\"_blank\">device code phishing branch<\/a> is a new addition to Greatness, allowing cybercriminals to leverage the OAuth device authorization grant flow to silently obtain tokens without user interaction.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOAHPHtHealarRuLqRBdjHny1bKMiOdEMFxIMIzw9gasI3Tk7MwVZJmYoZloQ4-g5yUyN_UjicJD37RoB2AabRGXYMbf6GQtpu93DeJHloU3CDOtvxgcn4ef8vZIrJRNX6CXsltA9m_GY9FLLsOKBnJcq0ERXt1T6tG6gG-EvvEzUk_SXXaBUYdKjschQ0\/s1700-e365\/bar.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOAHPHtHealarRuLqRBdjHny1bKMiOdEMFxIMIzw9gasI3Tk7MwVZJmYoZloQ4-g5yUyN_UjicJD37RoB2AabRGXYMbf6GQtpu93DeJHloU3CDOtvxgcn4ef8vZIrJRNX6CXsltA9m_GY9FLLsOKBnJcq0ERXt1T6tG6gG-EvvEzUk_SXXaBUYdKjschQ0\/s1700-e365\/bar.jpg\" alt=\"\" border=\"0\" data-original-height=\"628\" data-original-width=\"1200\"\/><\/a><\/div>\n<p>\u00abThe first big shift was adversary-in-the-middle phishing, where a proxy site sits between the user and Microsoft and relays the login in real time to capture the session cookie,\u00bb Trend Micro <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/g\/device-code-phishing.html\" target=\"_blank\">said<\/a> in an analysis published late last month.<\/p>\n<p>\u00abDevice code phishing is the next step, and in some ways, it is cleaner for the attacker. There is no fake login site to build or to get blocked, and there is nothing visually wrong for the user to notice, because the page they enter their password on really is Microsoft. The only unusual thing is a short code and a plausible reason to enter it.\u00bb<\/p>\n<p>Recent campaigns relying on the PhaaS kit have used spoofed RingCentral voicemail lures that bypass email gateways by taking advantage of safe sender exclusions and land on the victims&#8217; inbox despite failing SPF, DKIM, and DMARC checks. This, in turn, exploits the fact that the target is a legitimate RingCentral customer.<\/p>\n<p>While threat actors have <a href=\"https:\/\/www.ringcentral.com\/us\/en\/blog\/tips-for-avoiding-phishing-scams\/\" target=\"_blank\">impersonated<\/a> RingCentral in <a href=\"https:\/\/www.sonicwall.com\/blog\/deceptive-pdf-disguised-as-ringcentral-leads-to-phishing-attacks\" target=\"_blank\">various<\/a> phishing campaigns <a href=\"https:\/\/abnormal.ai\/threat-intelligence\/digest\/phisher-impersonates-ringcentral-sends-fake-voicemail-notification-steal-credentials\" target=\"_blank\">in the past<\/a>, the latest set of attacks adds a new dimension.<\/p>\n<p>\u00abThe emails are not merely impersonating RingCentral; they are exploiting the trust configuration that exists because the target is an actual RingCentral customer,\u00bb ZeroBEC said.<\/p>\n<p>\u00abAny vendor breach that exposes a customer list simultaneously exposes which organizations are likely to have that vendor&#8217;s domain on their safe sender lists. Defenders should treat vendor breach disclosures as a trigger to audit and tighten email exclusion rules for the affected vendor&#8217;s domains.\u00bb<\/p>\n<p>An analysis of post-compromise activity shows that harvested authentication tokens are replayed within minutes from dedicated proxy infrastructure, followed by enumerating various victim Microsoft 365 resources, such as Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars, and other registered applications, via the Microsoft Graph API.<\/p>\n<p>ZeroBEC said it observed one of the AiTM proxy IP addresses (\u00ab38.248.95[.]214\u00bb) actively authenticating against a victim&#8217;s Microsoft 365 account more than two weeks after the initial phishing campaign, indicating how the prolonged validity of the tokens can grant attackers continued access for extended periods.<\/p>\n<p>Other post-compromise actions <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/04\/06\/ai-enabled-device-code-phishing-campaign-april-2026\/\" target=\"_blank\">recorded<\/a> by Microsoft in conjunction with device code phishing attacks involve the threat actor registering new devices within minutes of the breach to generate a Primary Refresh Token (<a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/devices\/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa\" target=\"_blank\">PRT<\/a>) for long-term persistence, and waiting several hours before setting up malicious inbox rules or exfiltrating sensitive email data to avoid immediate detection.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The development comes as phishing <a href=\"https:\/\/blog.talosintelligence.com\/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdom\/\" target=\"_blank\">continues<\/a> to be the primary initial access vector, with attackers ramping up cascaded phishing campaigns, where the trust associated with a legitimate, compromised account is leveraged to launch hyper-personalized lures aimed at partners and third parties.<\/p>\n<p>Greatness is far from the only PhaaS kit to add device code phishing. In <a href=\"https:\/\/www.elastic.co\/security-labs\/tycoon-2fa-aitm-detection-engineering\" target=\"_blank\">recent months<\/a>, <a href=\"https:\/\/blog.barracuda.com\/2026\/04\/16\/threat-spotlight-tycoon-2fa-scattered-everywhere\" target=\"_blank\">campaigns<\/a> have <a href=\"https:\/\/www.okta.com\/blog\/threat-intelligence\/tycoon_2fa_phishing_actors_scatter\/\" target=\"_blank\">combined<\/a> Tycoon 2FA kit tradecraft with <a href=\"https:\/\/www.esentire.com\/blog\/tycoon-2fa-operators-adopt-oauth-device-code-phishing\" target=\"_blank\">OAuth device code authorization flows<\/a> despite a global law enforcement operation that disrupted 330 domains associated with the phishing service.<\/p>\n<p>\u00abThe device code phishing pages employ CAPTCHAs and use multi-hop redirect chains through legitimate infrastructure providers before the actual phishing page is shown,\u00bb Okta said back in May 2026. \u00abRecent device code phishing pages also employ similar anti-analysis techniques as Tycoon to attempt to deflect analysis.\u00bb<\/p>\n<p>Device code phishing attacks can be prevented by <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/policy-block-authentication-flows\" target=\"_blank\">blocking the authentication method<\/a> at a global level in Conditional Access Policies. It&#8217;s also advised to move to phishing-resistant MFA methods and teach employees to distrust unexpected codes.<\/p>\n<p>\u00abIf this flow is required in very specific use cases, those users\/resources should be explicitly excluded from the policies,\u00bb LevelBlue <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/go-with-the-flow-abusing-oauth-device-code-flow\" target=\"_blank\">noted<\/a>. \u00abThe permitted usage of this flow shall be continuously audited and revoked as soon as it&#8217;s no longer necessary.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2205,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[200,394,10,539,2878,1725,2498,390,571,146],"class_list":["post-2204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adds","tag-bypass","tag-code","tag-device","tag-greatness","tag-mfa","tag-phaas","tag-phishing","tag-steal","tag-tokens"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2204"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2204\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2205"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}