Threat reportMalwareTL-2026-1873

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens

highACTIVE

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and (TL-2026-1873), also tracked as Greatness, is a high-severity malware campaign, first published 2026-08-04. It is attributed to Greatness PhaaS Operators with medium confidence, affects Microsoft Microsoft 365 / Exchange Online, maps to 19 MITRE ATT&CK techniques (T1027, T1036, T1056.001), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
1Greatness PhaaS Operators
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1873

Threat ID
TL-2026-1873
Also known as
Greatness, Greatness PhaaS
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Greatness PhaaS Operators
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, health, technology, real-estate, construction, financial-services, legal, government administration, education, telecoms, energy, nonprofit
Target regions
united states of america, united kingdom, australia, canada, south africa, Europe, Middle East, North America, Asia
Detection rules
9
Indicators of compromise
29

Malware and tooling in Greatness PhaaS Adds Device Code Phishing to Bypass MFA and

Malware and tooling: EvilTokens, Greatness, telegram, Tycoon 2FA

How Greatness PhaaS Adds Device Code Phishing to Bypass MFA and works

The commercial Greatness phishing-as-a-service (PhaaS) toolkit now supports OAuth 2.0 Device Authorization Grant (device code) phishing, letting affiliates silently obtain authentication tokens that bypass MFA. Distributed via Telegram (3,250+ subscribers, $289/month), Greatness chains AiTM credential/session-cookie theft, device code phishing, and OAuth consent abuse against Microsoft 365 environments, with post-compromise persistence via Primary Refresh Token (PRT) generation and rogue device registration within minutes of breach.

Greatness is a commercial phishing-as-a-service toolkit first publicly documented by Cisco Talos in May 2023 and active since at least mid-2022, exclusively (and later primarily) targeting Microsoft 365 business users. The platform combines a phishing kit, a backend service API, and Telegram bot integration into a turnkey credential theft service. Affiliates pay a $289/month subscription (up from $120/month in January 2024), and access is brokered through the public Telegram channel @GreatnessPage (3,250+ subscribers), the @gr8managerbot provisioning bot, and developer handle @greatnessmgr. Operator panel login requires a user ID plus a 9-character license key, and provisioned operator domains follow the format api-[token].[base-domain]. The dashboard offers campaign statistics, captured cookies, a victim heat map, and configuration of phishing domains, CAPTCHA type, background theme, and cookie save method, plus 11+ downloadable lure templates (AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer and variants) packaged as ZIPs containing pre-built HTML, PDF redirectors, SVGs, and letter templates.

Greatness's original and still-core capability is an adversary-in-the-middle (AiTM) proxy: the phishing kit and backend relay credentials and MFA challenges in real time to the legitimate Microsoft 365 login page, stealing usernames, passwords, and authenticated session cookies. The kit dynamically pulls the target organization's real logo and background from the Microsoft 365 login page to build convincing lures, and the API blocks unwanted IPs from viewing phishing pages to impede researchers and sandboxes. In 2026 the platform added OAuth 2.0 Device Authorization Grant phishing. This abuses the legitimate device code flow: the attacker's backend requests a device code from Microsoft's /oauth2/v2.0/devicecode endpoint using a legitimate first-party client ID, then social-engineers the victim into visiting the real microsoft.com/devicelogin page and entering the code. Because the page the user authenticates against really is Microsoft, there is no fake login site to detect; MFA is genuinely satisfied by the victim, and the resulting access token (60-90 min) and rolling refresh token (up to 90 days) are issued to the attacker's client. When the Microsoft Authentication Broker client ID is used, a single approval can yield rogue device registration and long-lived refresh tokens.

Campaigns attributed to the Greatness ecosystem (operators tracked by Microsoft as Storm-1295) use five-stage redirect chains with anti-analysis protections, User-Agent fingerprinting, and CAPTCHA gates before the victim reaches either the AiTM proxy or a device code endpoint. In an August 2026 campaign documented by ZeroBEC, spoofed RingCentral voicemail and performance-review emails sent from service@ringcentral.com landed in victim inboxes despite failing SPF, DKIM, and DMARC, because RingCentral sat on organizations' safe-sender allow lists — achieving a Spam Confidence Level (SCL) of -1 in Exchange. ZeroBEC links the campaign's targeting lists to the July 28, 2026 RingCentral data breach (claimed by ShinyHunters), noting that any vendor breach exposing a customer list simultaneously reveals which organizations likely whitelist that vendor's domain. Similar tradecraft is documented across the 2026 device-code phishing wave: dynamic device-code generation (the 15-minute code countdown starts only when the victim clicks), clipboard hijacking to copy the code, backend polling every 3-5 seconds, and multi-hop redirect chains through Vercel, Cloudflare Workers, and AWS Lambda. Backend token-harvesting infrastructure runs on Railway.com (PaaS), whose clean IP reputation and email-only signup made it attractive.

Post-compromise, harvested tokens are replayed within minutes from dedicated proxy/VPS infrastructure. One observed Greatness AiTM proxy IP (38.248.95.214) was still actively authenticating against a victim's Microsoft 365 account more than two weeks after the initial phishing campaign, demonstrating the prolonged validity of stolen refresh tokens. Attackers enumerate victim M365 resources — Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars, and registered applications — via the Microsoft Graph API, and register new devices within minutes of a breach to generate a Primary Refresh Token (PRT) for long-term persistence. They commonly wait several hours before creating malicious inbox rules or exfiltrating sensitive email to avoid detection, and in financial-exfiltration variants search mail for wire-transfer details, pending invoices, and executive correspondence. Related device-code PhaaS kits — EvilTokens (advertised February 2026, whose backend was assessed as likely AI-generated, with endpoints for PRT conversion, OWA session cookies, and parallel Graph reconnaissance) and Tycoon 2FA operators who dispersed to device-code flows after a March 2026 Europol-led takedown of 330 domains — show the technique becoming a productized cybercrime service.

The attack is not a product vulnerability: Microsoft explicitly notes that device code phishing exploits an industry-standard authentication flow whose session is not strongly bound to the original requester, and that no defect enables it. Defensive guidance centers on blocking the device code authentication method in Conditional Access, moving to phishing-resistant MFA, auditing safe-sender lists, revoking tokens via revokeSignInSessions and disabling accounts (access tokens can remain valid ~1 hour after revocation unless Continuous Access Evaluation is enabled), restricting device registration, and hunting for the documented sign-in indicators (ErrorCode 50199 followed by 0, anonymous-IP and threat-intelligence risk events, and new device registrations correlated with token activity).

MITRE ATT&CK techniques used in TL-2026-1873

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Credential Access

T1056.001 Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Discovery

T1069.003 Cloud Groups; T1087.004 Cloud Account

Command and Control

T1090 Proxy

Persistence

T1098.005 Device Registration

Collection

T1114.002 Remote Email Collection; T1530 Data from Cloud Storage

Execution

T1204.001 Malicious Link

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Exfiltration

T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Greatness PhaaS Adds Device Code Phishing to Bypass MFA and

  • Microsoft — Microsoft 365 / Exchange Online
    Vulnerable versions: All tenants with the OAuth device code flow enabled
  • Microsoft — Microsoft Entra ID (Azure AD)
    Vulnerable versions: Device authorization grant (OAuth 2.0) exposed via /oauth2/v2.0/devicecode and /devicelogin
  • Microsoft — Outlook / SharePoint / OneDrive / Teams
    Vulnerable versions: Cloud resources reachable with stolen access/refresh tokens
  • Apple — iCloud
    Vulnerable versions: Accounts targeted by Greatness (reported 2026 expansion)
  • Google — Google Workspace / Yahoo
    Vulnerable versions: Accounts targeted by Greatness (reported 2026 expansion)
  • RingCentral — Cloud communications platform
    Vulnerable versions: Customer base spoofed in voicemail lures; July 28, 2026 breach (ShinyHunters) likely supplied targeting lists

Remediation for Greatness PhaaS Adds Device Code Phishing to Bypass MFA and

Immediate actions

  • Block the OAuth 2.0 device code authentication method globally in Microsoft Entra Conditional Access policies; exclude only explicitly-required identities
  • Audit and tighten safe-sender/allow-list exclusions that let spoofed vendor email (e.g., service@ringcentral.com) bypass SPF/DKIM/DMARC and spam filtering (SCL -1)
  • Revoke access and refresh tokens for compromised accounts via revokeSignInSessions (Graph API) and temporarily disable the account — access tokens can remain valid ~1 hour after revocation
  • Block known attacker infrastructure (Railway.com 162.220.232.0/22 and 162.220.234.0/22; HZ Hosting 89.150.45.0/24 and 185.81.113.0/24; AiTM proxy 38.248.95.214) via Conditional Access Named Locations

Workarounds

  • Where the device code flow is required, explicitly scope it to named users/resources and continuously audit and revoke usage when no longer necessary
  • Block legacy authentication and require compliant/managed devices for Exchange Online and SharePoint — device code authentication cannot proceed on non-compliant devices

Longer-term hardening

  • Move to phishing-resistant MFA (FIDO2 security keys, passkeys, Microsoft Authenticator passkey); avoid telephony-based MFA (SIM-jacking risk)
  • Enable Continuous Access Evaluation (CAE) to reduce token-revocation latency from ~1 hour to minutes
  • Enable token protection and restrict device enrollment to managed, compliant devices; audit OAuth consents and registered devices continuously
  • Monitor Graph API mail access (MailItemsAccessed), inbox/transport rule creation, and new device registrations correlated with risky sign-ins
  • Train users to distrust unexpected device codes and any 'verify identity' prompt delivered out-of-band

Timeline of Greatness PhaaS Adds Device Code Phishing to Bypass MFA and

  • Greatness PhaaS first observed in the wild, active since at least mid-2022 and targeting Microsoft 365 business users
  • First documented activity spike in Greatness phishing attachments (VirusTotal samples)
  • Second documented activity spike in Greatness phishing attachments
  • Cisco Talos publicly documents the Greatness PhaaS toolkit, detailing the AiTM proxy architecture and Telegram integration
  • Greatness subscription priced at $120/month as of January 2024
  • Microsoft discloses Storm-2372 device code phishing campaign — the same OAuth flow Greatness later productizes
  • Greatness adds 'one-way hash protection' for stolen cookies, accessible only via the customer's Telegram account 2FA code
  • EvilTokens device-code PhaaS kit first advertised on Telegram (NOIRLEGACY GROUP)
  • Device code phishing campaign targeting 344+ organizations observed; Railway.com PaaS token-harvesting abuse documented by Huntress
  • Europol-led operation disrupts 330 Tycoon 2FA domains; operators disperse and adopt device code flows with CAPTCHA and multi-hop redirect chains
  • Microsoft publishes 'Inside an AI-Enabled Device Code Phishing Campaign' detailing dynamic code generation, clipboard hijacking, and X-Antibot-Token backend
  • RingCentral discloses data breach (claimed by ShinyHunters); ZeroBEC says it likely supplied the customer lists used in Greatness RingCentral voicemail lures
  • ZeroBEC reports Greatness now supports device code phishing and OAuth consent abuse; price rises to $289/month; AiTM proxy IP observed active 2+ weeks post-campaign

Sources cited for Greatness PhaaS Adds Device Code Phishing to Bypass MFA and

Detection coverage for TL-2026-1873

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1873 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats