← Back to blog

Greatness PhaaS Now Bypasses MFA via Device Code Phishing

The Greatness phishing-as-a-service platform now leverages OAuth 2.0 device code flows to steal tokens and circumvent multi-factor authentication. This adds to the growing trend of adversary-in-the-middle attacks targeting enterprise credentials.

TL;DR

  • Greatness PhaaS now supports device code phishing to bypass MFA
  • Abuses OAuth 2.0 Device Authorization Grant flow
  • Targets enterprise users to steal access tokens covertly
  • Represents escalation in commercially available crimeware tools
  • Organizations should monitor for unusual device auth requests

Cybercriminals using the Greatness phishing-as-a-service (PhaaS) toolkit can now bypass multi-factor authentication (MFA) through device code phishing. This technique exploits the OAuth 2.0 Device Authorization Grant flow, allowing attackers to steal access tokens without triggering traditional security alerts.

The addition marks a significant evolution in the capabilities of commercially available crimeware platforms. By leveraging legitimate authentication protocols, these attacks can appear more trustworthy to both users and security systems, increasing their chances of success.

How Device Code Phishing Works

  • Attackers initiate a legitimate OAuth 2.0 device authorization request on behalf of a malicious app
  • Victims receive a prompt to enter a code on a separate device, typically via a browser
  • When users comply, they unknowingly grant access to their accounts without direct password exposure
  • MFA prompts may still occur but are often accepted by users who believe they initiated the login

Implications for Enterprise Security

  • Traditional credential theft protections may fail against these OAuth-based attacks
  • Security teams need to monitor for anomalous device authorization grant patterns
  • User training should emphasize verification of device code requests before approval
  • Conditional access policies should restrict unnecessary OAuth application permissions
  • Token theft via this method can lead to persistent account compromise across services

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Greatness PhaaS Now Bypasses MFA via Device Code Phishing — Agent Breach Blog | Agent Breach