Greatness PhaaS Exploits MFA with Device Code Phishing

Greatness PhaaS Exploits MFA with Device Code Phishing

First seen 4 Aug 2026, 20:26 UTC ThehackernewsFeeds.4SysopsCybersecuritynewsGbhackersthehacker.news 86% similarity 64.5

Article Content

Browse articles
ThreatCluster

The Greatness phishing-as-a-service (PhaaS) platform has introduced device-code phishing, allowing attackers to harvest multi-factor authentication (MFA) tokens without needing victims' passwords. This method enables sustained access to Microsoft 365 tenants for over two weeks after the initial phishing attack. The attack leverages adversary-in-the-middle techniques and OAuth consent abuse, significantly increasing the risk of unauthorized access. The persistence of access tokens highlights a shift in attack vectors, focusing on token replay rather than traditional password theft. This new capability has raised concerns among security professionals regarding the effectiveness of existing MFA implementations. The Greatness platform's capabilities were documented by Cisco Talos and Hornet Security, indicating a growing trend in sophisticated phishing attacks targeting enterprise environments.

Key Points: • Greatness PhaaS now enables device-code phishing to bypass MFA. • Attackers can maintain access to Microsoft 365 accounts for over two weeks. • The method emphasizes token replay over traditional password theft.

ThreatCluster AI How this analysis works

Timeline

2023-05-01
Cisco Talos documents token replay attacks
Cisco Talos reported on the persistence of token replay attacks in the AiTM PhaaS ecosystem, highlighting vulnerabilities in MFA implementations.
Gbhackers
2026-08-04
Greatness PhaaS adds device-code phishing
Greatness platform introduces new phishing capabilities, allowing attackers to harvest MFA tokens without passwords, enhancing their attack vectors.
Feeds.4Sysops
2026-08-04
Greatness PhaaS exploits MFA vulnerabilities
The platform's new features enable attackers to bypass MFA and obtain valid access tokens, posing a significant risk to Microsoft 365 users.
Thehackernews

Community

Browse all →

Tracked Entities in This Story