← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Greatness PhaaS Adds Device Code Phishing, Targets Microsoft 365 Accounts

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Greatness PhaaS now supports device code phishing.
  • Exploits OAuth 2.0 Device Authorization Grant to bypass MFA.
  • Targets Microsoft 365, iCloud, Yahoo, and Google Workspace.
  • Sold for $289/month via Telegram channel.
  • Uses spoofed RingCentral emails to bypass security filters.

Greatness PhaaS Expands Capabilities

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has incorporated support for device code phishing. This method abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and gain control of user accounts. This addition signifies an evolution in PhaaS platforms from simple credential harvesting to more integrated attack ecosystems.

Integrated Attack Features

According to a report by ZeroBEC, Greatness now supports Adversary-in-the-Middle (AiTM) credential and token theft, device code phishing, and OAuth consent abuse. These functionalities are accessible from a single operator panel and share a common backend infrastructure. The platform targets multiple services, including iCloud, Yahoo, and Google Workspace, in addition to Microsoft 365.

Targeting Microsoft 365 Users

Greatness has been active since at least mid-2022, primarily targeting Microsoft 365 business users in the United States, Canada, the UK, Australia, and South Africa. In recent campaigns, Greatness operators have impersonated the RingCentral communications platform, using spoofed emails from service@ringcentral[.]com. These emails, often containing fake voicemail or performance-review notifications, are designed to bypass email security filters and entice recipients to open them.

Availability and Cost

The Greatness platform is available for purchase by cybercriminals for $289 per month. It is distributed through a Telegram channel that has thousands of subscribers. This pricing model lowers the barrier of entry for threat actors seeking to conduct sophisticated phishing attacks.

Broader Trend in PhaaS

The expansion of Greatness's capabilities reflects a broader trend within the PhaaS landscape. These platforms are moving beyond basic credential theft to offer more advanced attack vectors, such as token theft and OAuth abuse. This evolution allows attackers to maintain access to compromised accounts for extended periods, increasing the threat to online security.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Greatness phishing-as-a-service platform is using spoofed RingCentral emails to bypass security filters and conduct adversary-in-the-middle (AiTM) and device-code phishing attacks against Microsoft 365 accounts. This evolution in tactics allows attackers to steal MFA-approved authentication tokens and maintain access to compromised accounts for extended periods.

The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, a method that exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and compromise user accounts. This update signifies a trend of PhaaS platforms evolving from simple credential harvesting to integrated attack ecosystems, posing a greater threat to online security.