top of page
perceptive_background_267k.jpg

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Published:

4 augustus 2026 om 19:27:39

Alert date:

4 augustus 2026 om 20:03:19

Source:

thehackernews.com

Click to open the original link from this advisory

Identity & Access, Email & Messaging, Ransomware & Malware, Web Technologies

The Greatness phishing-as-a-service (PhaaS) toolkit has added support for device code phishing, leveraging the OAuth 2.0 Device Authorization Grant flow to bypass Multi-Factor Authentication (MFA). This technique, known as adversary-in-the-middle (AiTM), allows attackers to steal authentication tokens without needing the victim's credentials directly. Device code phishing is a rapidly growing threat vector that abuses legitimate authentication protocols. Greatness is a commercial crimeware toolkit, making these advanced capabilities accessible to a wider range of threat actors. The addition of device code phishing to Greatness signals an escalation in the sophistication of phishing-as-a-service offerings. Organizations relying solely on MFA for account protection may be at increased risk from this attack method. Token theft enables attackers to seize control of user accounts and potentially access cloud services and enterprise applications.

Technical details

Greatness is a commercial Phishing-as-a-Service (PhaaS) toolkit active since at least mid-2022, first documented by Cisco Talos in May 2023. It has expanded its capabilities to include: (1) Adversary-in-the-Middle (AiTM) credential and session cookie theft via a real-time proxy between victim and Microsoft; (2) Device Code Phishing abusing the OAuth 2.0 Device Authorization Grant flow to silently obtain tokens without building a fake login page — the victim authenticates on the legitimate Microsoft page but a device code is used to capture tokens; (3) OAuth consent abuse; all managed from a single operator panel. The platform targets Microsoft 365, iCloud, Yahoo, and Google Workspace. Victims are delivered phishing emails (e.g., spoofed RingCentral voicemail lures) that bypass email gateways by exploiting safe sender exclusions, even when SPF, DKIM, and DMARC checks fail. Clicking a link traverses a five-stage redirect chain with anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before reaching an AiTM proxy or device code endpoint. Post-compromise, harvested tokens are replayed within minutes from dedicated proxy infrastructure. Attackers enumerate Microsoft 365 resources (Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars) via Microsoft Graph API. Threat actors also register new devices within minutes of breach to generate a Primary Refresh Token (PRT) for long-term persistence, then wait several hours before setting malicious inbox rules or exfiltrating email data. One AiTM proxy IP was observed authenticating against a victim's M365 account more than two weeks after initial compromise. The platform is sold via Telegram (@GreatnessPage, 3,250+ subscribers) starting at $289/month, managed via @gr8managerbot and @greatnessmgr. Operator domains follow the format: api-[token].[base-domain]. The dashboard includes campaign statistics, heat maps of victims, CAPTCHA selection, phishing domain configuration, and 11+ lure templates (AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer, etc.) packaged as ZIP files with pre-built HTML, PDF redirectors, SVGs, and letter templates.

Mitigation steps:

1. Block the OAuth 2.0 Device Authorization Grant authentication flow at a global level using Microsoft Entra Conditional Access Policies (policy-block-authentication-flows). If the flow is required for specific use cases, explicitly exclude only those users/resources and continuously audit and revoke access when no longer needed. 2. Migrate to phishing-resistant MFA methods (e.g., FIDO2/passkeys) that are not susceptible to AiTM or device code phishing attacks. 3. Train employees to be suspicious of unexpected device codes and to avoid entering codes unless they explicitly initiated a device login flow. 4. Audit and tighten email safe sender exclusion rules, especially following vendor breach disclosures, as vendor customer lists can be exploited to bypass email gateway protections. 5. Monitor Microsoft Graph API activity for anomalous enumeration of resources (Outlook, Teams, SharePoint, Exchange, OneDrive) shortly after authentication events. 6. Monitor for new device registrations occurring within minutes of authentication, which may indicate PRT generation for persistence. 7. Watch for delayed malicious inbox rule creation (hours after initial breach) and anomalous email exfiltration activity. 8. Block and monitor the known AiTM proxy IP: 38.248.95[.]214. 9. Monitor for authentication activity from unexpected IP addresses days or weeks after initial phishing campaigns. 10. Apply Conditional Access policies to detect and block token replay attacks from anomalous locations or devices.

Affected products:

Microsoft 365
Microsoft Entra ID (Azure AD)
Microsoft Outlook
Microsoft Teams
Microsoft SharePoint
Microsoft Exchange
Microsoft OneDrive
iCloud
Yahoo Mail
Google Workspace
RingCentral (impersonated/abused for lures)

Related links:

https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html
https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html
https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
https://thehackernews.com/2023/05/new-phishing-as-service-platform-lets.html
https://thehackernews.com/2024/05/new-tricks-in-phishing-playbook.html
https://thehackernews.com/2024/01/malicious-ads-on-google-target-chinese.html
https://t.me/GreatnessPage/125
https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
https://www.ringcentral.com/us/en/blog/tips-for-avoiding-phishing-scams/
https://www.sonicwall.com/blog/deceptive-pdf-disguised-as-ringcentral-leads-to-phishing-attacks
https://abnormal.ai/threat-intelligence/digest/phisher-impersonates-ringcentral-sends-fake-voicemail-notification-steal-credentials
https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/
https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa
https://blog.talosintelligence.com/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdom/
https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering
https://www.okta.com/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/
https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing
https://thehackernews.com/2026/03/europol-led-operation-takes-down-tycoon.html
https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
https://www.levelblue.com/blogs/spiderlabs-blog/go-with-the-flow-abusing-oauth-device-code-flow

Related CVE's:

Related threat actors:

IOC's:

38.248.95[.]214 (AiTM proxy IP address observed authenticating against victim Microsoft 365 accounts), Telegram channel: @GreatnessPage, Telegram bot: @gr8managerbot, Telegram account: @greatnessmgr, Operator domain format: api-[token].[base-domain]

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page