Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal user accounts. This evolution reflects a broader trend in PhaaS platforms expanding beyond simple credential harvesting to integrated attack ecosystems. The kit, accessible via a Telegram channel for $289/month, utilizes a five-stage redirect chain and downloadable lures to facilitate attacks, including spoofed RingCentral voicemail lures that bypass email security measures. Device code phishing can be mitigated by blocking the authentication method at a global level and transitioning to phishing-resistant MFA.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
