Skip to content

Phishing-as-a-Service Kit “Greatness” Integrates Device Code Phishing for MFA Bypass

Bottom line: The PhaaS toolkit Greatness now supports device code phishing via the OAuth 2.0 device authorization grant, enabling MFA bypass and account takeover without intercepting a password or second factor.

The commercial phishing-as-a-service toolkit “Greatness” now supports device code phishing, a technique that abuses the legitimate OAuth 2.0 device authorization grant to bypass multi-factor authentication and take over accounts. This puts the kit among a growing number of criminal offerings actively marketing this attack method.

Greatness is an established, commercially distributed phishing-as-a-service toolkit that until now was mainly known for adversary-in-the-middle (AiTM) attacks used to harvest credentials. According to the underlying report, the operator has now added support for device code phishing. This technique exploits the OAuth 2.0 device authorization grant, a mechanism originally designed for devices without convenient input options, such as smart TVs or IoT devices, which sign in to a service using a code entered on a separate device.

When abusing this feature, attackers generate a legitimate authorization code with an identity provider, such as Microsoft Entra ID, and use social engineering to trick the victim into entering that code on a genuine sign-in page. Because the authentication technically proceeds through the official service, active MFA protection is not bypassed via fake login pages but is instead approved by the victim themselves. The attacker then receives valid access and refresh tokens, which allow them to impersonate the compromised account without needing to intercept a password or an additional second factor.

For security leaders, integration into an already circulating, commercially available PhaaS kit lowers the barrier to entry for this attack technique. While device code phishing has so far been attributed mainly to targeted, well-resourced attackers, the method is now potentially available to a broader range of cybercriminals as a ready-to-use tool, similar to how other PhaaS toolkits already offer classic AiTM credential phishing.

Since classic MFA factors such as one-time codes or push notifications remain ineffective against this attack pattern, organizations should assess to what extent the device code flow is actually needed in their environment and, if not, restrict or disable it via conditional access policies. In addition, targeted monitoring of sign-in events indicative of the device authorization grant is recommended, along with awareness measures that sensitize employees to requests to enter a code on an unfamiliar site or in an unexpected situation.


Source: thehackernews.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: