Feeds.4Sysops
Greatness PhaaS Introduces Device-Code Phishing for MFA Bypass
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Greatness, a phishing-as-a-service platform, has launched a new feature allowing attackers to perform device-code phishing, enabling them to harvest multi-factor authentication (MFA) tokens without needing victims' passwords. This method combines adversary-in-the-middle theft and OAuth consent abuse, effectively turning legitimate Microsoft sign-ins into MFA bypasses. The platform's capabilities pose a significant risk to enterprises relying on MFA for security. The attack vector can potentially impact a wide range of organizations that utilize Microsoft services for authentication. As of now, no specific incidents of exploitation have been reported, but the potential for widespread abuse is high given the ease of access to this tool. Security professionals are urged to remain vigilant against this emerging threat.
Key Points: • Greatness PhaaS now offers device-code phishing to bypass MFA. • Attackers can harvest valid access tokens without passwords. • The new feature combines multiple phishing techniques from a single dashboard.