Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Summary

The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing. This technique leverages the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal user tokens. The addition of this feature makes Greatness a more potent tool for attackers seeking to compromise accounts.

IFF Assessment

FOE

The addition of device code phishing to a PhaaS toolkit represents a new and effective method for attackers to bypass MFA and compromise user accounts, posing a significant threat to defenders.

Defender Context

Defenders need to be aware of the growing threat of device code phishing, as it circumvents traditional MFA measures. Organizations should implement additional security controls and educate users on how to identify and report such attacks. Monitoring for unusual authentication flows and token exfiltration is also crucial.

Read Full Story →