news.mlab.sh
Back to the feed
threat-intel

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

High
Image: The Hacker News
Summary

The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal user accounts. This evolution reflects a broader trend in PhaaS platforms expanding beyond simple credential harvesting to integrated attack ecosystems. The kit, accessible via a Telegram channel for $289/month, utilizes a five-stage redirect chain and downloadable lures to facilitate attacks, including spoofed RingCentral voicemail lures that bypass email security measures. Device code phishing can be mitigated by blocking the authentication method at a global level and transitioning to phishing-resistant MFA.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.