Greatness PhaaS Integrates Device Code Phishing to Bypass MFA

The phishing-as-a-service (PhaaS) platform known as Greatness has recently expanded its capabilities to include device code phishing, a method that exploits the OAuth 2.0 Device Authorization Grant to circumvent multi-factor authentication (MFA) and gain unauthorized access to user accounts.

Greatness now offers adversary-in-the-middle (AiTM) credential and token theft, device code phishing, and OAuth consent abuse, all managed through a unified operator panel and shared backend infrastructure. This evolution reflects a broader trend among PhaaS platforms, which are transitioning from simple credential harvesting to more sophisticated, integrated attack ecosystems.

Initially documented in May 2023, Greatness has been utilized by cybercriminals to target Microsoft 365 business users since at least mid-2022. The platform is accessible via a subscription model through its public Telegram channel, which boasts over 3,250 subscribers. Subscription plans start at $289 per month, a significant increase from the $120 per month reported in January 2024. Subscribers gain access to a comprehensive dashboard featuring campaign statistics, domain configuration options, CAPTCHA selection, and over 11 downloadable lure templates, including themes like voicemail notifications, document sharing, and QR codes.

Operator registration, license provisioning, and support are facilitated through a dedicated Telegram bot, while licenses can be procured or renewed by contacting the platform’s developer handle. The operators emphasize user privacy, claiming that stolen cookies are securely stored using one-way hash protection, accessible only to customers via their Telegram account’s two-factor authentication (2FA) code.

Upon successful registration, customers receive an operator-specific domain and can access a dashboard that provides detailed campaign statistics, including captured cookies and a heat map of victims. The dashboard also allows for phishing domain selection, CAPTCHA type configuration, background theme customization, and cookie storage method selection. Additionally, the attachments section offers a variety of ready-to-use phishing lure templates packaged as ZIP files.

The integration of device code phishing into Greatness’s suite of tools underscores the platform’s commitment to staying ahead in the cybercrime landscape. This method exploits legitimate OAuth 2.0 device authorization flows, originally designed for devices with limited input capabilities, to deceive users into granting access to their accounts. By incorporating this technique, Greatness enables attackers to bypass MFA protections, posing a significant threat to organizations relying on such security measures.

As PhaaS platforms like Greatness continue to evolve and offer more sophisticated attack vectors, it is imperative for organizations to enhance their security protocols. This includes educating users about emerging phishing techniques, implementing robust monitoring systems to detect unauthorized access, and adopting adaptive authentication methods that can respond to evolving threats. The rapid advancement of PhaaS platforms highlights the need for a proactive and comprehensive approach to cybersecurity.