The Greatness Phishing-as-a-Service (PhaaS) toolkit has recently introduced device code phishing to its array of cybercrime tactics. This development leverages the OAuth 2.0 Device Authorization Grant, posing a significant risk by enabling the circumvention of Multi-Factor Authentication (MFA) protections and allowing unauthorized access to user accounts.
Advancements in Phishing Capabilities
Greatness now supports a variety of phishing techniques, including adversary-in-the-middle (AiTM) credential theft, device code phishing, and OAuth consent abuse. These features are managed through a unified operator panel and backend infrastructure, as reported by ZeroBEC. The platform’s ability to target multiple services, such as iCloud and Google Workspace, marks a shift from basic credential theft to more sophisticated attack strategies.
Initially documented by Cisco Talos in May 2023, the Greatness toolkit has been used by cybercriminals to exploit Microsoft 365 users since mid-2022. Its subscription model, accessible via a Telegram channel with over 3,250 subscribers, lowers entry barriers for aspiring attackers, offering extensive phishing resources and tools.
Subscription and Operational Features
Subscriptions to Greatness start at $289 per month, offering access to a dashboard with campaign statistics, domain settings, and numerous pre-configured phishing templates. These templates cover scenarios like voicemail and QR code phishing, simplifying the setup process for users. Operational support is provided through a Telegram bot, ensuring seamless license management and updates.
Subscribers gain access to a comprehensive dashboard featuring campaign analytics, victim heatmaps, and customizable phishing elements. The dashboard also facilitates the selection of phishing domains, CAPTCHA types, and cookie storage methods, enhancing the user experience for attackers.
Implications and Defensive Measures
Recent attacks utilizing Greatness have employed spoofed RingCentral voicemail lures, exploiting safe sender exclusions to bypass security checks. This tactic underscores the need for organizations to reassess email trust configurations following vendor breaches, as exposed customer lists can lead to targeted phishing efforts.
Post-compromise activities include the rapid exploitation of stolen authentication tokens, enabling attackers to access various Microsoft 365 services. Prolonged token validity poses a continuous threat, as observed when attackers used the same proxy infrastructure weeks after the initial breach.
Conclusion and Future Considerations
As phishing remains a predominant access vector, the evolution of PhaaS platforms like Greatness highlights the growing sophistication of cyber threats. Organizations are encouraged to adopt phishing-resistant MFA methods and educate employees on recognizing phishing attempts. Continuous auditing of authentication flows is also recommended to mitigate risks associated with device code phishing.
