Greatness, a commercial phishing-as-a-service toolkit, now includes device code phishing capabilities that exploit legitimate OAuth 2.0 Device Authorization Grant flows to circumvent MFA protections and harvest user tokens.
Device code phishing operates by tricking users into approving authentication requests on legitimate-looking devices. Attackers intercept the OAuth flow before users complete verification, allowing them to bypass MFA entirely and gain account access without needing actual passwords or one-time codes. This attack vector abuses a standard authentication mechanism designed for headless devices like smart TVs and IoT hardware.
The addition of this capability to Greatness represents a significant expansion of the toolkit's attack surface. Greatness already supported adversary-in-the-middle (AiTM) credential harvesting and session token theft. The device code phishing module transforms it into a comprehensive account takeover platform, enabling operators to target organizations across multiple authentication vectors simultaneously.
The threat spans enterprise and consumer environments. Attackers can launch device code phishing campaigns against Microsoft 365, Google Workspace, and other cloud services. Users receive phishing emails directing them to approve sign-in requests, but the malicious device flow intercepts the transaction. Once approved, attackers obtain refresh tokens granting persistent access independent of password changes.
Organizations relying solely on MFA face exposure. Device code phishing bypasses traditional MFA because it exploits the authorization protocol before MFA verification completes. Standard passwordless security approaches that depend on OAuth device flows remain vulnerable.
Defense requires behavioral anomaly detection and conditional access policies. Organizations should implement Continuous Access Evaluation (CAE) to revoke tokens if suspicious activity occurs post-authentication. Educating users about unsolicited device approval requests remains critical, though sophisticated phishing campaigns make this difficult.
The Greatness PhaaS platform operates in the cybercriminal
