Skip to content
Greatness PhaaS Exploits MFA with Device Code Phishing

Greatness PhaaS Exploits MFA with Device Code Phishing

First seen 4 Aug 2026, 20:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 5, 2026 at 19:32 UTC
  • Greatness PhaaS now enables device-code phishing to bypass MFA.
  • Attackers can maintain access to Microsoft 365 accounts for over two weeks.
  • The method emphasizes token replay over traditional password theft.

The Greatness phishing-as-a-service (PhaaS) platform has introduced device-code phishing, allowing attackers to harvest multi-factor authentication (MFA) tokens without needing victims' passwords. This method enables sustained access to Microsoft 365 tenants for over two weeks after the initial phishing attack. The attack leverages adversary-in-the-middle techniques and OAuth consent abuse, significantly increasing the risk of unauthorized access. The persistence of access tokens highlights a shift in attack vectors, focusing on token replay rather than traditional password theft. This new capability has raised concerns among security professionals regarding the effectiveness of existing MFA implementations. The Greatness platform's capabilities were documented by Cisco Talos and Hornet Security, indicating a growing trend in sophisticated phishing attacks targeting enterprise environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2023-05-01
Cisco Talos documents token replay attacks
Cisco Talos reported on the persistence of token replay attacks in the AiTM PhaaS ecosystem, highlighting vulnerabilities in MFA implementations.
Gbhackers
2026-08-04
Greatness PhaaS adds device-code phishing
Greatness platform introduces new phishing capabilities, allowing attackers to harvest MFA tokens without passwords, enhancing their attack vectors.
Feeds.4Sysops
2026-08-04
Greatness PhaaS exploits MFA vulnerabilities
The platform's new features enable attackers to bypass MFA and obtain valid access tokens, posing a significant risk to Microsoft 365 users.
Thehackernews

More articles in this cluster (7)