Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Forg365 is a phishing-as-a-service (PhaaS) operation that uses device code phishing, AitM tactics, and AI-assisted lures to compromise Microsoft 365 accounts. It…
The Quarry is a PhaaS kit developed by a lone operator named RockyBelling, used for credential theft via emails mimicking IRS, SSA,…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
EvilTokens is a phishing kit released in February 2026 that significantly lowered the barrier to entry for device code phishing. Its availability…
ZeroBEC is a cybersecurity firm that analyzed the Greatness PhaaS kit, detailing its new device code phishing and AiTM capabilities. The report…
Cisco Talos first publicly documented the Greatness phishing platform in May 2023, highlighting its use in attacks targeting Microsoft 365 business users…