Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Greatness PhaaS's Addition of Device Code Phishing: A New Layer of Complexity in Cybercrime


Greatness PhaaS's latest development has added device code phishing to its arsenal, marking a significant escalation in the use of PhaaS platforms in cybercrime. This move highlights the evolving nature of cybercrime and emphasizes the need for robust security measures and education about the risks associated with phishing attacks.

  • The new phishing-as-a-service (PhaaS) toolkit called Greatness has added support for device code phishing to its arsenal, escalating the use of PhaaS platforms in cybercrime.
  • Greatness was first publicly documented by Cisco Talos in May 2023 and was initially used to target Microsoft 365 business users since mid-2022.
  • The addition of device code phishing to Greatness allows attackers to bypass Multi-Factor Authentication (MFA) and seize control of user accounts silently.
  • The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms.
  • The impact of Greatness's addition to device code phishing is significant, opening up new avenues for attackers to exploit vulnerabilities in user accounts.
  • Organizations must ensure that their security protocols are up-to-date and effective in detecting and preventing such attacks.
  • Users must be vigilant and cautious when interacting with suspicious emails or links, and use 2FA codes to protect their accounts.


  • The recent development in the world of cybercrime has seen the emergence of a new phishing-as-a-service (PhaaS) toolkit known as Greatness, which has added support for device code phishing to its arsenal. This move marks a significant escalation in the use of PhaaS platforms in cybercrime, with implications that are far-reaching and complex.

    Greatness is not a newcomer to the world of cybercrime. It was first publicly documented by Cisco Talos in May 2023, highlighting how threat actors were incorporating it into their attacks to target Microsoft 365 business users since at least mid-2022. However, its latest development has taken it to new heights, adding device code phishing to its capabilities.

    The addition of device code phishing to Greatness is a significant departure from the traditional methods used by cybercriminals. Device code phishing is a technique that leverages the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. This method is particularly effective, as it allows attackers to silently obtain tokens without user interaction.

    According to ZeroBEC, the developer of Greatness, the platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. The addition of this feature has significantly expanded the capabilities of Greatness, making it a more formidable tool for cybercriminals.

    The impact of Greatness's addition to device code phishing cannot be overstated. It has opened up new avenues for attackers to exploit vulnerabilities in user accounts, with significant consequences for individuals and organizations. The use of device code phishing also raises concerns about the effectiveness of current security measures.

    In recent months, campaigns have combined Tycoon 2FA kit tradecraft with OAuth device code authorization flows, despite a global law enforcement operation that disrupted 330 domains associated with the phishing service. This highlights the cat-and-mouse game that is played between cybercriminals and security agencies.

    The development of Greatness's device code phishing feature has significant implications for organizations. It emphasizes the need for robust security measures to protect user accounts from exploitation. Organizations must ensure that their security protocols are up-to-date and effective in detecting and preventing such attacks.

    Furthermore, the addition of device code phishing to Greatness underscores the importance of educating users about the risks associated with phishing attacks. Users must be vigilant and cautious when interacting with emails or links that seem suspicious. The use of 2FA codes can also help protect user accounts from exploitation.

    The emergence of PhaaS platforms like Greatness highlights the evolving nature of cybercrime. As security measures become more sophisticated, cybercriminals adapt and evolve to stay ahead of their adversaries. The addition of device code phishing to Greatness is a prime example of this evolution.

    In conclusion, the recent development in Greatness's capabilities has significant implications for individuals and organizations. It underscores the need for robust security measures and education about the risks associated with phishing attacks. As cybercrime continues to evolve, it is essential that security agencies and organizations stay vigilant and adapt their strategies to counter such threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Greatness-PhaaSs-Addition-of-Device-Code-Phishing-A-New-Layer-of-Complexity-in-Cybercrime-ehn.shtml

  • https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html


  • Published: Tue Aug 4 13:22:12 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us