Interestana
Home/News/Greatness PhaaS Adds Device Code Phishing to Bypass MFA
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Greatness PhaaS Adds Device Code Phishing to Bypass MFA

Greatness PhaaS Adds Device Code Phishing to Bypass MFA

The commercial phishing-as-a-service (PhaaS) toolkit named Greatness has incorporated support for device code phishing, a technique that exploits the legitimate OAuth 2.0 Device Authorization Grant. This new capability allows the toolkit to bypass Multi-Factor Authentication (MFA) and gain unauthorized access to user accounts by stealing authentication tokens. Device code phishing represents a significant evolution in cyber threats, moving beyond traditional credential harvesting to actively circumvent security measures designed to protect user accounts. The OAuth 2.0 Device Authorization Grant is a legitimate protocol that enables devices without direct input capabilities, such as smart TVs or gaming consoles, to authorize access to online services. Attackers abuse this flow by tricking users into visiting a malicious link, which then prompts them to enter a device code on a fake authentication page. Once the user enters the code, the attacker's compromised application can obtain an access token, effectively impersonating the user and gaining access to their associated services. Greatness's integration of this method signifies a growing trend among cybercriminal toolkits to adopt sophisticated techniques that directly target and undermine modern authentication protocols. This development poses a heightened risk to organizations and individuals, as standard MFA protections may no longer be sufficient against such advanced phishing attacks. The toolkit's ability to perform adversary-in-the-middle (AiTM) attacks, which involve intercepting and relaying communication between a user and a legitimate service, further amplifies its threat potential. By combining AiTM with device code phishing, Greatness can effectively steal both credentials and session tokens, granting attackers persistent access to compromised accounts. This sophistication in crimeware highlights the continuous arms race between cybersecurity defenders and malicious actors. The adoption of device code phishing by a commercial PhaaS offering like Greatness suggests that this attack vector is becoming more accessible and widely used within the cybercriminal underground. Security researchers are closely monitoring the evolution of such toolkits to develop effective countermeasures. Organizations are advised to implement additional security layers beyond standard MFA, such as continuous authentication monitoring and user education on recognizing sophisticated phishing attempts. The threat landscape continues to evolve, with attackers increasingly leveraging legitimate protocols and advanced techniques to achieve their objectives. The integration of device code phishing into Greatness PhaaS underscores the need for adaptive and robust security strategies to protect against emerging cyber threats.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next