Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
Tycoon2FA is a well-known AiTM phishing kit that added device code phishing support in May 2026. It was previously tracked as the…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Forg365 is a phishing-as-a-service (PhaaS) operation that uses device code phishing, AitM tactics, and AI-assisted lures to compromise Microsoft 365 accounts. It…
Kali365 is a phishing-as-a-service platform that offers both AiTM and device code phishing capabilities. It was the subject of a standalone FBI…
Okta reported in May 2026 that recent device code phishing pages employ CAPTCHAs and multi-hop redirect chains through legitimate infrastructure providers. These…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
Storm-2372 is a nation-state threat actor that was among the first to use device code phishing in the wild, starting in 2024.…