HackMyIP
← Back to News
2026-08-04 The Hacker News

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

PhishingAuthenticationThreat Intel

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has evolved into a more dangerous offering, adding support for device code phishing to its existing arsenal of adversary-in-the-middle (AiTM) credential theft and OAuth consent abuse. According to a report from ZeroBEC shared with The Hacker News, the platform now abuses the legitimate OAuth 2.0 Device Authorization Grant flow to bypass multi-factor authentication (MFA) protections and hijack user sessions across iCloud, Yahoo, Google Workspace, and Microsoft 365 environments. This convergence of techniques, all managed from a single operator panel, reflects how PhaaS developers are shifting from simple credential harvesting toward integrated, multi-stage attack ecosystems that target authentication infrastructure itself. Organizations concerned about credential exposure can start by running an email breach checker to determine whether employee accounts have already appeared in known stealer logs.

Access to Greatness is brokered through a public Telegram channel (@GreatnessPage) with more than 3,250 subscribers, where aspiring cybercriminals can subscribe starting at $289 per month, a sharp increase from the $120 monthly price reported in January 2024. Subscribers receive an operator dashboard featuring campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates spanning voicemail lures, document sharing notifications, and QR codes. Operator registration, license provisioning, and support are handled through a dedicated Telegram bot (@gr8managerbot), while billing is coordinated via the @greatnessmgr developer handle. First publicly documented by Cisco Talos in May 2023, Greatness has been used to target Microsoft 365 business users since at least mid-2022, underscoring how long-running crimeware kits continue to expand their reach.

Device code phishing is particularly concerning because it weaponizes a legitimate authentication standard rather than exploiting a vulnerability. Attackers initiate the OAuth 2.0 device authorization flow on a legitimate service, receive a short-lived user code and verification URL, and then trick the victim into entering that code on a genuine login page, completing MFA in the process. Once authorized, the operator harvests the resulting refresh token for persistent access. Security teams should harden conditional access policies, restrict legacy authentication, and review OAuth app consent grants, while individual users can verify their overall exposure with a privacy checkup and rotate any credentials that may have been compromised.

In a November 2025 Telegram post, the Greatness operators claimed that stolen cookies are protected by one-way hashing and can only be extracted by customers using their Telegram account's 2FA code, framing this as a privacy guarantee. The post emphasized that the service has been operating for eight years and stressed customer honesty as a differentiator. While the marketing language is standard for crimeware-as-a-service operations, it does not change the underlying risk: subscribers are purchasing a turnkey platform engineered to defeat MFA and exfiltrate authentication tokens at scale. Defenders should treat any interaction with Greatness infrastructure as a high-fidelity indicator of compromise and audit suspicious device code authorizations in Entra ID and Google Cloud logs immediately.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →