Skip to main content
Emerging ThreatsMalware & Ransomware

Greatness PhaaS Expands to Device Code Phishing

Modern office setting with laptop, phone, and paper with scribbles on a desk.

"Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," ZeroBEC said.

Greatness: AiTM, device code phishing, and OAuth consent abuse

Greatness, a commercial phishing-as-a-service (PhaaS) toolkit first documented publicly by Cisco Talos in May 2023, has expanded from basic credential harvesting into an integrated crimeware ecosystem. According to ZeroBEC, the platform now packages adversary-in-the-middle (AiTM) token theft, device code phishing, OAuth consent abuse, and support for multiple target platforms — including iCloud, Yahoo, and Google Workspace — behind a single operator dashboard and shared backend.

The platform offers operators downloadable lure templates (ZeroBEC lists more than 11, including AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, and VideoPlayer), campaign statistics, domain configuration, CAPTCHA selection, and cookie/capture options that are accessible once a subscription is purchased.

OAuth 2.0 Device Authorization Grant abused as a stealth path

Device code phishing leverages the legitimate OAuth 2.0 Device Authorization Grant flow, allowing attackers to obtain authentication tokens without the normal visual cues of a fake login page. Trend Micro described the shift from AiTM proxies to device code phishing as a step that can be "cleaner for the attacker," because "there is no fake login site to build or to get blocked, and there is nothing visually wrong for the user to notice, because the page they enter their password on really is Microsoft."

Okta reported in May 2026 that recent device code phishing pages employ CAPTCHAs and multi-hop redirect chains through legitimate infrastructure providers and use anti-analysis techniques similar to other kits such as Tycoon. The result is an attack that can feel normal to users — a short code entry prompted for a plausible reason — while handing tokens to the attacker.

Telegram channel, bot, and subscription economics

Greatness markets access through a public Telegram channel (@GreatnessPage) with more than 3,250 subscribers, and operator onboarding is handled via a Telegram bot (@gr8managerbot). Licenses and renewals are processed by messaging the developer handle "@greatnessmgr." ZeroBEC and The Hacker News report that subscriptions now start at $289 per month, up from the $120-per-month figure cited in January 2024.

Registration requires a Telegram chat ID and a bot API token, and operators log in with a user ID and a 9-character license key. Successful registration provisions an operator-specific domain in the format "api-[token].[base-domain]" and provides access to a dashboard that displays captured cookies, a victim heat map, link configuration, CAPTCHA type, background theme, and lure attachments packaged as ZIP files.

In a November 2025 post referenced by ZeroBEC, Greatness operators claim that stolen cookies are protected via one-way hashing and that access to logs is tied to a customer's Telegram account 2FA code.

Five-stage redirect chains, AiTM proxies, and token replay

Observed campaigns route victims through a five-stage redirect chain that implements anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate before landing on either an AiTM proxy or a device code endpoint. Recent lures have impersonated RingCentral voicemail and exploited safe-sender exclusions to bypass email gateways — landing in inboxes despite failing SPF, DKIM, and DMARC checks because targets were legitimate RingCentral customers.

ZeroBEC documented post-compromise behavior in Microsoft 365 environments: harvested authentication tokens are replayed within minutes from dedicated proxy infrastructure and used to enumerate Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars, and other registered applications via the Microsoft Graph API. One AiTM proxy IP (38.248.95[.]214) was observed authenticating against a victim's Microsoft 365 account more than two weeks after the initial campaign, illustrating prolonged token validity.

Microsoft also recorded actors registering new devices quickly to generate Primary Refresh Tokens (PRTs) for long-term persistence, and waiting several hours before creating malicious inbox rules or exfiltrating sensitive mail to reduce immediate detection.

What this means for technologists, enterprise defenders, and end users

  • Technologists and security teams: The report identifies specific mitigations — notably blocking the device code authentication method via Conditional Access Policies and moving to phishing-resistant MFA methods. LevelBlue advised that if the device code flow is required for specific users or resources, those exceptions should be explicitly managed and continuously audited.
  • Enterprise defenders and procurement leaders: Vendor breach disclosures can reveal which organizations have a vendor's domain on safe-sender lists; ZeroBEC recommended treating such disclosures as triggers to audit and tighten email exclusion rules for affected vendor domains. Observed campaign mechanics (multi-hop redirects, CAPTCHA gates, and genuine infrastructure providers used in redirects) suggest detection must look beyond simple domain or SPF/DKIM/DMARC checks.
  • End users and IT policy owners: Okta and Trend Micro note the human-factor angle — device code phishing often looks legitimate and may present only a short code to enter. Training to distrust unexpected codes and to prefer phishing-resistant MFA are the specific behavioral counters cited in the reporting.

Greatness's evolution from credential harvesting to an all-in-one phishing toolbox — available for a monthly fee and distributed through Telegram — underscores how commercialized cybercrime is integrating new OAuth-based tradecraft. Defenders can act on concrete controls named in the reporting, but the documented persistence of captured tokens (including replay weeks later) raises the harder question the reporting leaves clear: once tokens are issued, how quickly and thoroughly can organizations detect and revoke them?

https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html