Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Greatness PhaaS, a commercial phishing-as-a-service toolkit, has added support for device code phishing, a rapidly growing cyber threat that bypasses Multi-Factor Authentication (MFA) and steals user tokens.
Intelligence analysis by Llama

Greatness PhaaS has expanded its capabilities to include device code phishing, allowing cybercriminals to leverage the OAuth device authorization grant flow to silently obtain tokens without user interaction. This new feature is part of the platform's evolution from simple credential harvesting to integrated attack ecosystems.
Greatness PhaaS is a tool that helps cybercriminals steal user accounts by sending fake emails that look like they're from a real company. The tool has added a new feature that allows it to steal user tokens without the user even knowing. This is a big problem because it can let the cybercriminals take control of user accounts and do bad things.
Analysis
A Growing Threat to User Accounts
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
According to a report shared with The Hacker News, Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure. The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace.
This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems. The phishing platform was first publicly documented by Cisco Talos in May 2023, highlighting how threat actors are incorporating it in their attacks to target Microsoft 365 business users since at least mid-2022.
A Barrier-Lowering Solution
Designed as a way to lower the barrier of entry for cybercrime, access to Greatness is facilitated through a subscription available on its public-facing Telegram channel (@GreatnessPage) that has more than 3,250 subscribers and serves as a central hub for announcements and feature updates. Aspiring cybercriminals can obtain a subscription starting from $289 per month, up from the $120 per month figure reported back in January 2024.
The subscription provides access to an operator that includes a dashboard with campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates covering voicemail, document sharing, and QR codes, among others. Operator registration, license provisioning, and support are offered via a dedicated Telegram bot (@gr8managerbot), while licenses can be procured or renewed by sending a message to the "@greatnessmgr" account, the developer handle that oversees operator support and platform development.
A New Dimension in Phishing
Recent campaigns relying on the PhaaS kit have used spoofed RingCentral voicemail lures that bypass email gateways by taking advantage of safe sender exclusions and land on the victims' inbox despite failing SPF, DKIM, and DMARC checks. This, in turn, exploits the fact that the target is a legitimate RingCentral customer. While threat actors have impersonated RingCentral in various phishing campaigns in the past, the latest set of attacks adds a new dimension.
The emails are not merely impersonating RingCentral; they are exploiting the trust configuration that exists because the target is an actual RingCentral customer. Any vendor breach that exposes a customer's information can be used to create a convincing phishing email that exploits the trust relationship between the vendor and the customer.
Implications for User Security
The addition of device code phishing to Greatness PhaaS highlights the growing threat of cybercrime and the need for robust security measures to protect user accounts. As cybercriminals continue to evolve their tactics and tools, it is essential for users to remain vigilant and take proactive steps to secure their accounts.
In conclusion, the Greatness PhaaS toolkit has added support for device code phishing, a rapidly growing cyber threat that bypasses MFA and steals user tokens. This new feature is part of the platform's evolution from simple credential harvesting to integrated attack ecosystems. As cybercriminals continue to evolve their tactics and tools, it is essential for users to remain vigilant and take proactive steps to secure their accounts.
Key points
- Greatness PhaaS has added support for device code phishing, a rapidly growing cyber threat that bypasses MFA and steals user tokens.
- The phishing platform was first publicly documented by Cisco Talos in May 2023, highlighting how threat actors are incorporating it in their attacks to target Microsoft 365 business users since at least mid-2022.
- Recent campaigns relying on the PhaaS kit have used spoofed RingCentral voicemail lures that bypass email gateways by taking advantage of safe sender exclusions and land on the victims' inbox despite failing SPF, DKIM, and DMARC checks.
- The addition of device code phishing to Greatness PhaaS highlights the growing threat of cybercrime and the need for robust security measures to protect user accounts.
If users remain vigilant and take proactive steps to secure their accounts, the impact of device code phishing can be mitigated. Additionally, the evolution of PhaaS platforms like Greatness can lead to the development of more effective security measures to protect user accounts.
The addition of device code phishing to Greatness PhaaS highlights the growing threat of cybercrime and the need for robust security measures to protect user accounts. If users do not take proactive steps to secure their accounts, the impact of device code phishing can be severe.



