Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

August 4, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Enterprise users of Microsoft 365, Google Workspace, and iCloud
Incident: Integration of device code phishing into the Greatness PhaaS toolkit to facilitate MFA bypass.
Impact: Unauthorized account takeover and session hijacking despite active MFA protections.
Attacker: Greatness PhaaS operators and their subscribers
Analysis: Greatness has transitioned from basic credential harvesting to a comprehensive attack ecosystem. By integrating device code phishing and AiTM token theft, it can bypass multi-factor authentication across major platforms like Google and Microsoft. This evolution lowers the technical barrier for low-skill actors to execute sophisticated session hijacking attacks.
Recommendations: Implement phishing-resistant MFA such as FIDO2 or WebAuthn; Disable the OAuth 2.0 Device Authorization Grant in Conditional Access Policies unless strictly necessary; Train employees to distrust and report unexpected device code prompts
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *