Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Enterprise users of Microsoft 365, Google Workspace, and iCloud
Incident: Integration of device code phishing into the Greatness PhaaS toolkit to facilitate MFA bypass.
Impact: Unauthorized account takeover and session hijacking despite active MFA protections.
Attacker: Greatness PhaaS operators and their subscribers
Analysis: Greatness has transitioned from basic credential harvesting to a comprehensive attack ecosystem. By integrating device code phishing and AiTM token theft, it can bypass multi-factor authentication across major platforms like Google and Microsoft. This evolution lowers the technical barrier for low-skill actors to execute sophisticated session hijacking attacks.
Recommendations: Implement phishing-resistant MFA such as FIDO2 or WebAuthn; Disable the OAuth 2.0 Device Authorization Grant in Conditional Access Policies unless strictly necessary; Train employees to distrust and report unexpected device code prompts
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source