importantSYS.SOURCE: The Hacker News• 2026-08-04T22:57:39+05:30
Greatness PhaaS Integrates Device Code Phishing to Bypass MFA and Steal Tokens
Greatness PhaaS now employs device code phishing via OAuth 2.0 to bypass MFA and steal tokens, targeting Microsoft 365 and other platforms. The technique uses spoofed emails and proxy infrastructure to maintain long-term access to compromised accounts.
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
"Greatness supports AiTM [adversary-in-the-middle] credential and
*** END OF TRANSMISSION ***