The Greatness phishing-as-a-service platform has integrated device code phishing capabilities, allowing cybercriminals to bypass multi-factor authentication and hijack Microsoft 365 accounts using legitimate OAuth 2.0 authorization flows.
Key Points
- The Greatness platform now supports adversary-in-the-middle (AiTM) token theft, OAuth consent abuse, and device code phishing from a centralized operator dashboard.
- Subscriptions for the crimeware toolkit are available via Telegram for $289 per month, providing access to over 11 pre-built phishing lure templates.
- Attackers use device code phishing to trick users into entering authorization codes on legitimate Microsoft pages, silently capturing tokens without needing fake login sites.
- Recent campaigns have exploited trust in legitimate vendors like RingCentral to bypass email security filters and deliver highly personalized phishing lures.
- Stolen authentication tokens are used to access Microsoft 365 resources, including Outlook, Teams, and SharePoint, often via the Microsoft Graph API.