The commercial phishing-as-a-service toolkit Greatness has expanded to support device code phishing, a fast-growing cyber threat that exploits the legitimate OAuth 2.0 Device Authorization Grant to circumvent Multi-Factor Authentication and take over user accounts. ZeroBEC detailed the PhaaS kit's latest capabilities in a report shared with The Hacker News, noting that the platform now integrates adversary-in-the-middle credential and token theft, device code phishing, and OAuth consent abuse through a single operator panel. First publicly documented by Cisco Talos in May 2023, Greatness has targeted Microsoft 365 business users since at least mid-2022 and now extends coverage to iCloud, Yahoo, and Google Workspace.
Access to the toolkit is sold through a subscription model advertised on its public Telegram channel, which has more than 3,250 subscribers and functions as a hub for announcements and feature updates. Cybercriminals can purchase a subscription starting at $289 per month, up from $120 per month reported in January 2024. The subscription grants access to an operator dashboard featuring campaign statistics, domain configuration, CAPTCHA selection, and over 11 downloadable lure templates covering voicemail, document sharing, and QR codes. Operator registration, license provisioning, and support are handled via a dedicated Telegram bot, while licenses can be obtained or renewed by messaging the "@greatnessmgr" account, the developer handle that manages operator support and platform development. Customers who provide their Telegram chat ID and a bot API token access the panel through an "O365 Panel" login page requiring a user ID and a 9-character license key, then receive a dashboard and an operator-specific domain.
The report notes that victims who click a malicious link in the phishing email pass through a five-stage redirect chain implementing anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before reaching either an adversary-in-the-middle proxy or a device code endpoint. According to ZeroBEC, observed templates include AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer, and additional variants, each containing pre-built HTML, PDF redirectors, SVGs, and letter templates that lower the barrier to entry so operators don't need to build lures from scratch. Recent campaigns using the PhaaS kit have deployed spoofed RingCentral voicemail lures that bypass email gateways by exploiting safe sender exclusions and land in victims' inboxes despite failing SPF, DKIM, and DMARC checks, specifically targeting organizations that are legitimate RingCentral customers.
The device code phishing technique represents a shift from adversary-in-the-middle attacks because it allows attackers to silently obtain tokens without user interaction and without building a fake login site that can be blocked, according to an analysis Trend Micro published late last month. Analysis of post-compromise activity shows that harvested authentication tokens are replayed within minutes from dedicated proxy infrastructure, followed by enumeration of various victim Microsoft 365 resources such as Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars, and other registered applications via the Microsoft Graph API. ZeroBEC observed one adversary-in-the-middle proxy IP address actively authenticating against a victim's Microsoft 365 account more than two weeks after the initial phishing campaign, demonstrating how the prolonged validity of tokens grants attackers continued access for extended periods. Microsoft noted that other post-compromise actions involve the threat actor registering new devices within minutes of the breach to generate a Primary Refresh Token for long-term persistence, then waiting several hours before setting up malicious inbox rules or exfiltrating sensitive email data to avoid immediate detection.
Device code phishing attacks can be prevented by blocking the authentication method at a global level in Conditional Access Policies, the report states. LevelBlue recommends that if this flow is required in very specific use cases, those users or resources should be explicitly excluded from the policies, and the permitted usage should be continuously audited and revoked as soon as it's no longer necessary. The report also advises organizations to move to phishing-resistant MFA methods and teach employees to distrust unexpected codes, while defenders should treat vendor breach disclosures as a trigger to audit and tighten email exclusion rules for the affected vendor's domains. The combination of device code phishing with commercial PhaaS platforms signals a consolidation of attack techniques that once required separate infrastructure, making sophisticated account takeover campaigns accessible to a wider range of threat actors. Organizations relying solely on traditional MFA as a defense now face an adversary ecosystem that has systematically engineered workarounds into affordable, user-friendly toolkits.

