# MFA Is Not Enough Anymore: Greatness PhaaS Now Ships Device Code Phishing Out of the Box


For three years, Greatness has been the go-to phishing kit for criminals who want enterprise-grade Microsoft 365 attacks without enterprise-grade technical skills. It was already dangerous. Now it's added something that should alarm every security team relying on MFA as their last line of defense.


Greatness has integrated device code phishing — an attack technique that doesn't try to steal your password at all. It steals your session token after you've already authenticated, MFA and all.


## What Device Code Phishing Actually Does


The attack abuses a legitimate OAuth 2.0 flow called the Device Authorization Grant. That flow was designed for devices without keyboards — smart TVs, printers, gaming consoles — that need to authenticate to cloud services. The legitimate version works like this: the device displays a short code, you go to a URL on your phone or laptop, enter the code, and the device gets a token.


The criminal version inverts this. The attacker initiates the OAuth flow themselves, generates a real device code from Microsoft's infrastructure, then socially engineers the victim into authorizing it. The victim visits a legitimate Microsoft URL, logs in with their real credentials, completes their MFA challenge, and clicks "Allow." They've just handed the attacker a long-lived access token with full account permissions — and no stolen password was involved.


This isn't a new technique. Nation-state actors have used it for years. Midnight Blizzard (APT29) was caught using device code phishing against government and diplomatic targets in early 2024. Storm-0539, the gift card fraud ring, used it to compromise retail employees. What's new is that Greatness has packaged it alongside adversary-in-the-middle token interception and OAuth consent abuse in a single operator panel, available to anyone willing to pay a monthly subscription.


## The Industrialization of an APT Technique


That's the real story here. Device code phishing was, until recently, the domain of sophisticated threat actors who understood OAuth internals well enough to weaponize them. It required custom tooling and some operational finesse.


Greatness charges $289 per month for access — up from $120 in January 2024, a 140 percent price increase that reflects strong criminal market demand, not inflation. For that fee, a subscriber gets a dashboard with campaign statistics and victim heat maps, eleven-plus downloadable lure templates (voicemail, OneDrive, QR code, video player, among others), domain configuration, CAPTCHA options, and now a three-mode attack suite: AiTM token theft, device code phishing, and OAuth consent abuse.


The Telegram channel that serves as the platform's storefront has more than 3,250 subscribers. Not all of them are paying operators, but that's a substantial audience for a criminal SaaS product. The platform's operators claim eight years in the business and advertise that they hash stolen cookies before storage, accessible only to customers via Telegram 2FA. Whether that privacy claim is genuine or marketing copy is irrelevant — the sophistication of the customer experience is real.


Microsoft 365 was Greatness's original hunting ground, which tracks: M365 is the enterprise identity backbone for millions of organizations, and its Conditional Access policies and MFA prompts give defenders a false sense of security that device code attacks specifically dismantle. But ZeroBEC's analysis confirms the platform has expanded beyond M365 to iCloud, Yahoo, and Google Workspace. The addressable market for these attacks just grew significantly.


## What Your MFA Actually Stops (and What It Doesn't)


Most organizations implemented MFA after seeing breach statistics that showed password-only authentication failing under credential stuffing and phishing. MFA with SMS codes or authenticator apps genuinely does stop those attacks. But it was never designed to stop someone from tricking you into authorizing a legitimate OAuth token request.


The distinction matters enormously for defenders thinking about control selection. SMS and TOTP codes stop attackers who don't have your password. They do nothing against an attacker who initiates a valid authentication flow and waits for you to complete it yourself. The credential never gets captured. The MFA factor gets satisfied legitimately. The victim logs in as they normally would, and the attacker walks away with a functional token.


Phishing-resistant MFA — FIDO2 hardware keys like YubiKeys, Windows Hello for Business, or passkeys bound to the relying party domain — actually closes this gap because the cryptographic assertion is tied to the originating domain. A device code flow initiated by an attacker doesn't satisfy that binding.


## HackWire Analysis


The Greatness update is a useful forcing function for a conversation the security industry has been deferring: the era of MFA as a binary "protected / not protected" control is over.


Device code phishing joins a pattern of attacks — AiTM proxies like Evilginx and Modlishka, token theft from browser memory, OAuth app consent abuse — that all share the same design insight: don't break authentication, route around it. The common thread is that they target the session token that authentication produces, not the credentials that produce it.


The timing is notable. Microsoft has made Conditional Access policies more accessible and nudged organizations toward MFA for years. That push worked — MFA adoption in enterprise M365 environments is genuinely high. But raising MFA adoption created a large population of organizations that checked the MFA box and considered themselves protected from phishing. Greatness, and tools like it, are deliberately constructed to monetize that false confidence.


What defenders should actually do right now: audit your OAuth app registrations for any apps granted broad permissions that you don't recognize; review Conditional Access policies for device code flow restrictions (Microsoft allows you to block or limit the Device Authorization Grant in Entra ID); and evaluate your organization's actual exposure to phishing-resistant MFA. If the answer to that last question is "we use an authenticator app," you're not covered against this.


The 3,250-subscriber Telegram channel for a $289/month criminal SaaS product is also worth sitting with. This is not a sophisticated threat actor with nation-state resources. This is a business with customer support, a product roadmap, and a Telegram bot for license provisioning. Treating the adversary as anything less organized than that is how organizations end up surprised.


— HackWire Editorial


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)