
Greatness PhaaS Deploys Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing kit Greatness has added a new tactic: device code phishing, a technique that abuses the OAuth 2.0 Device Authorization Grant to bypass multi-factor authentication and steal users' tokens. According to a ZeroBEC report, the platform now supports AiTM credential and token theft, device code phishing, and OAuth consent abuse from the same operator panel. It can target iCloud, Yahoo, and Google Workspace, reflecting a shift from simple credential harvesting to a broader attack ecosystem. Greatness was first publicly documented by Cisco Talos in May 2023, after threat actors had been using it to target Microsoft 365 business users since at least mid-2022. Subscriptions now start at $289 per month, up from $120 reported in January 2024. Operators get a dashboard with campaign statistics, domain configuration, CAPTCHA selection, and more than 11 lure templates covering voicemail, document sharing, and QR codes. Licenses and support are handled through Telegram accounts @gr8managerbot and @greatnessmgr. Victims who click a malicious email link go through a five-stage redirect chain with anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before reaching an AiTM proxy or a device code endpoint. The device code flow is especially hard to spot because victims enter their password on a legitimate Microsoft page; they are only asked for a short code and a plausible reason to enter it. Recent campaigns abused RingCentral's trusted status by spoofing voicemail lures that landed in inboxes despite failing SPF, DKIM, and DMARC checks, because the target was a real RingCentral customer. After compromise, stolen tokens are replayed within minutes from proxy infrastructure to enumerate Microsoft 365 resources such as Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, and calendars. Researchers saw one AiTM proxy IP address still authenticating against a victim account more than two weeks after the campaign. Attackers also register new devices to obtain Primary Refresh Tokens for long-term persistence, sometimes waiting hours before creating malicious inbox rules or exfiltrating data. Device code phishing is not limited to Greatness; recent campaigns have combined Tycoon 2FA kit tradecraft with OAuth device code flows even after a law enforcement operation disrupted 330 domains. Researchers recommend blocking device code authentication globally in Conditional Access policies, moving to phishing-resistant MFA, and teaching users to distrust unexpected codes. Somali organizations that depend on Microsoft 365 or Google Workspace—from remittance firms to public offices—should act before an account is hit. A stolen token can keep an attacker inside sensitive data for weeks, and the low price of phishing kits puts that capability within reach of regional criminals.
Read our sourcing and corrections policy



Be the first to comment on this story!