Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Summary
The commercial phishing-as-a-service toolkit known as Greatness has added support for device code phishing, abusing the legitimate OAuth 2.0 Device Authorisation Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
Details
The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms including iCloud, Yahoo, and Google Workspace. ZeroBEC identified the expansion, noting that PhaaS platforms are evolving from simple credential harvesting to integrated attack ecosystems. Device code phishing โ which Microsoft had previously warned about in relation to the Storm 2372 campaign โ is rapidly becoming a standard technique in the cybercrime toolkit, posing significant challenges for organisations relying on Mfa as their primary authentication control.
Sources
- The Hacker News
- raw/digests/Cyber-Digest-2026-08-05