Greatness PhaaS Toolkit Evolves with Device Code Phishing, Threatening MFA Defenses
The commercial phishing-as-a-service (PhaaS) platform **Greatness** has significantly upgraded its capabilities, now supporting device code phishing. This new feature allows threat actors to bypass Multi-Factor Authentication (MFA) by exploiting the legitimate OAuth 2.0 Device Authorization Grant, posing a heightened risk to IT security professionals and privacy-conscious users.
The **Greatness** phishing-as-a-service (PhaaS) toolkit is rapidly evolving, integrating sophisticated techniques like device code phishing to bypass robust security measures such as Multi-Factor Authentication (MFA). This development marks a significant escalation in the tools available to cybercriminals, making it easier for them to compromise user accounts.
### Greatness: A Multifaceted Threat
According to a report by **ZeroBEC**, **Greatness** now offers a comprehensive suite of attack vectors from a single operator panel. "Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," **ZeroBEC** stated. The platform also targets multiple major platforms, including **iCloud**, **Yahoo**, and **Google Workspace**, showcasing its broad reach and adaptability.
First documented by **Cisco Talos** in May 2023, **Greatness** has been actively used to target **Microsoft 365** business users since at least mid-2022. Its evolution from simple credential harvesting to an integrated attack ecosystem reflects a broader trend in the PhaaS landscape.
### Accessibility and Operations
**Greatness** lowers the entry barrier for cybercrime, offering subscriptions via its public **Telegram** channel (@GreatnessPage), which boasts over 3,250 subscribers. Subscription costs have risen to $289 per month, up from $120 earlier this year. This provides access to an operator panel featuring campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates for various phishing scenarios like voicemail, document sharing, and QR codes.
Operator registration and support are managed through a dedicated **Telegram** bot (@gr8managerbot), with licenses procured or renewed via the developer handle, "@greatnessmgr."
### Security Claims and Realities
In a **Telegram** post from November 2025, **Greatness** operators claimed to secure stolen cookies using one-way hash protection, accessible only by customers with their **Telegram** account's 2FA code. They emphasized user privacy, stating, "We respect all users' privacy because we have been in this business for 8 years and prioritize everything to provide you the best experience."
However, the operational model requires customers to provide their **Telegram** chat ID and a bot API token to access a dashboard secured by a user ID and a 9-character license key. Upon successful registration, a unique operator-specific domain is provisioned, typically in the format: "api-[token].[base-domain]."
### Advanced Attack Flow

The **Greatness** dashboard offers extensive campaign management, including captured cookie statistics and victim heat maps. It also provides a links configuration page for phishing domain selection, CAPTCHA type, background themes, and cookie saving methods. The attachments section includes over 11 ready-to-use phishing lure templates, such as "AudioLogin," "ChatAssistance," "WindowsExplorer," "Voicemail," "OneDrive," "QR," and "VideoPlayer."
Victims engaging with these malicious links are subjected to a five-stage redirect chain, incorporating anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate. This eventually leads them to either an AiTM proxy or a device code endpoint.
### The Rise of Device Code Phishing
Device code phishing is a new and potent addition to **Greatness**, leveraging the **OAuth** device authorization grant flow to obtain tokens silently. **Trend Micro** highlighted the shift, stating, "The first big shift was adversary-in-the-middle phishing, where a proxy site sits between the user and Microsoft and relays the login in real time to capture the session cookie. Device code phishing is the next step, and in some ways, it is cleaner for the attacker."
This method is particularly insidious because it eliminates the need for fake login sites, making it harder for users to detect. Users interact directly with legitimate vendor pages, entering a short code provided by the attacker, which makes the attack visually indistinguishable from a normal login process.
### Real-World Impact and Post-Compromise Actions
Recent campaigns utilizing **Greatness** have involved spoofed **RingCentral** voicemail lures. These attacks bypass email gateways by exploiting safe sender exclusions, allowing emails to land in inboxes despite failing SPF, DKIM, and DMARC checks. This is particularly effective when the target is a legitimate **RingCentral** customer, leveraging existing trust configurations.
**ZeroBEC** warned, "Any vendor breach that exposes a customer list simultaneously exposes which organizations are likely to have that vendor's domain on their safe sender lists. Defenders should treat vendor breach disclosures as a trigger to audit and tighten email exclusion rules for the affected vendor's domains."
Post-compromise analysis reveals that harvested authentication tokens are replayed within minutes from dedicated proxy infrastructure. Attackers then enumerate various **Microsoft 365** resources, including **Outlook**, **Teams**, **SharePoint**, **Exchange**, and **OneDrive**, via the **Microsoft Graph API**. **ZeroBEC** observed one AiTM proxy IP address ("38.248.95[.]214") maintaining access to a victim's **Microsoft 365** account for over two weeks, demonstrating the prolonged validity of stolen tokens.
**Microsoft** has also recorded similar post-compromise actions, noting that threat actors register new devices within minutes of a breach to generate a Primary Refresh Token (**PRT**) for long-term persistence. To evade immediate detection, attackers often wait several hours before establishing malicious inbox rules or exfiltrating sensitive email data.