hacker-news · Crawled Aug 4, 2026
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
5 IoCs
Read original article ↗
AI Summary
The Greatness PhaaS (Phishing-as-a-Service) platform has added device code phishing capabilities to bypass Multi-Factor Authentication (MFA) by abusing the OAuth 2.0 Device Authorization Grant. This enables attackers to steal authentication tokens without presenting fake login pages, making detection more difficult. The service supports multiple phishing methods including adversary-in-the-middle (AiTM) attacks, OAuth consent abuse, and phishing for iCloud, Yahoo, and Google Workspace. Post-compromise, attackers use stolen tokens to access Microsoft 365 resources via Microsoft Graph API and establish persistence by registering new devices to obtain Primary Refresh Tokens (PRTs).
AI-extracted · verify before operational use