The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has incorporated support for device code phishing. This method abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and gain control of user accounts. This addition signifies an evolution in PhaaS platforms from simple credential harvesting to more integrated attack ecosystems.
According to a report by ZeroBEC, Greatness now supports Adversary-in-the-Middle (AiTM) credential and token theft, device code phishing, and OAuth consent abuse. These functionalities are accessible from a single operator panel and share a common backend infrastructure. The platform targets multiple services, including iCloud, Yahoo, and Google Workspace, in addition to Microsoft 365.
Greatness has been active since at least mid-2022, primarily targeting Microsoft 365 business users in the United States, Canada, the UK, Australia, and South Africa. In recent campaigns, Greatness operators have impersonated the RingCentral communications platform, using spoofed emails from service@ringcentral[.]com. These emails, often containing fake voicemail or performance-review notifications, are designed to bypass email security filters and entice recipients to open them.
The Greatness platform is available for purchase by cybercriminals for $289 per month. It is distributed through a Telegram channel that has thousands of subscribers. This pricing model lowers the barrier of entry for threat actors seeking to conduct sophisticated phishing attacks.
The expansion of Greatness's capabilities reflects a broader trend within the PhaaS landscape. These platforms are moving beyond basic credential theft to offer more advanced attack vectors, such as token theft and OAuth abuse. This evolution allows attackers to maintain access to compromised accounts for extended periods, increasing the threat to online security.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Greatness phishing-as-a-service platform is using spoofed RingCentral emails to bypass security filters and conduct adversary-in-the-middle (AiTM) and device-code phishing attacks against Microsoft 365 accounts. This evolution in tactics allows attackers to steal MFA-approved authentication tokens and maintain access to compromised accounts for extended periods.
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, a method that exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and compromise user accounts. This update signifies a trend of PhaaS platforms evolving from simple credential harvesting to integrated attack ecosystems, posing a greater threat to online security.