Greatness PhaaS adds OAuth device code phishing to bypass MFA and steal tokens
Source headline: Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Intelligence Summary
Greatness, a commercial phishing-as-a-service toolkit, has added device code phishing capabilities. The technique abuses the OAuth 2.0 Device Authorization Grant to trick users into completing sign-in flows. By leveraging device-code interactions, the campaign can bypass Multi-Factor Authentication and capture authorization artifacts such as tokens. The risk affects organizations relying on OAuth-based login and MFA controls. Users should review OAuth consent and device authorization activity and strengthen detections for token theft and anomalous device-code prompts.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.