AUTO-UPDATED

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness phishing-as-a-service platform has integrated device code phishing capabilities, allowing cybercriminals to bypass multi-factor authentication and hijack Microsoft 365 accounts using legitimate OAuth 2.0 authorization flows.

Key Points

  • The Greatness platform now supports adversary-in-the-middle (AiTM) token theft, OAuth consent abuse, and device code phishing from a centralized operator dashboard.
  • Subscriptions for the crimeware toolkit are available via Telegram for $289 per month, providing access to over 11 pre-built phishing lure templates.
  • Attackers use device code phishing to trick users into entering authorization codes on legitimate Microsoft pages, silently capturing tokens without needing fake login sites.
  • Recent campaigns have exploited trust in legitimate vendors like RingCentral to bypass email security filters and deliver highly personalized phishing lures.
  • Stolen authentication tokens are used to access Microsoft 365 resources, including Outlook, Teams, and SharePoint, often via the Microsoft Graph API.

Why it Matters

The evolution of phishing-as-a-service kits into integrated attack ecosystems significantly lowers the barrier for entry, allowing even unskilled actors to execute sophisticated, high-impact account takeovers. Organizations must move beyond traditional MFA and implement phishing-resistant authentication methods while auditing Conditional Access Policies to restrict the abuse of OAuth device authorization flows.
Internet Published by info@thehackernews.com (The Hacker News)
Read original