The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal authentication tokens. According to a report by ZeroBEC shared with The Hacker News, Greatness now supports adversary-in-the-middle (AiTM) credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure. The platform targets multiple platforms, including iCloud, Yahoo, and Google Workspace, reflecting a broader trend of PhaaS platforms evolving from simple credential harvesting to integrated attack ecosystems.
First documented by Cisco Talos in May 2023, Greatness has been used to target Microsoft 365 business users since at least mid-2022. Access is facilitated through a subscription available on its public Telegram channel (@GreatnessPage), which has over 3,250 subscribers. Subscriptions start at $289 per month, up from $120 in January 2024. The operator dashboard provides campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates, including voicemail, document sharing, and QR codes. Licenses are managed via a Telegram bot (@gr8managerbot), and support is provided through the @greatnessmgr account.
Victims who interact with a malicious link are taken through a five-stage redirect chain with anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before reaching either an AiTM proxy or a device code endpoint. The device code phishing branch is a new addition, allowing attackers to silently obtain tokens without user interaction. Recent campaigns have used spoofed RingCentral voicemail lures that bypass email gateways by exploiting safe sender exclusions, even when failing SPF, DKIM, and DMARC checks. Post-compromise activity shows harvested tokens are replayed within minutes from dedicated proxy infrastructure, and attackers enumerate victim Microsoft 365 resources via the Microsoft Graph API. In one observed case, an AiTM proxy IP address actively authenticated against a victim’s account more than two weeks after the initial campaign.
Device code phishing attacks can be mitigated by blocking the authentication method globally in Conditional Access Policies, adopting phishing-resistant MFA, and training employees to distrust unexpected codes. If the flow is required for specific use cases, those resources should be explicitly excluded and continuously audited.
CVEs: CVE-2026-50522
Malware: Greatness, Tycoon 2FA
Companies: ZeroBEC, Cisco Talos, Trend Micro, Okta, LevelBlue, RingCentral, Microsoft
Products: Microsoft 365, Microsoft Graph API
Original source: thehackernews.com