Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens — Threadlinqs Intelligence
As of 2026-08-04, Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens is a high-severity malware threat attributed to Greatness PhaaS Operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1873 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Greatness PhaaS Operators · FINANCIAL
The commercial Greatness phishing-as-a-service (PhaaS) toolkit now supports OAuth 2.0 Device Authorization Grant (device code) phishing, letting affiliates silently obtain authentication tokens that
Greatness is a commercial phishing-as-a-service toolkit first publicly documented by Cisco Talos in May 2023 and active since at least mid-2022, exclusively (and later primarily) targeting Microsoft 365 business users. The platform combines a phishing kit, a backend service API, and Telegram bot integration into a turnkey credential theft service. Affiliates pay a $289/month subscription (up from $120/month in January 2024), and access is brokered through the public Telegram channel @GreatnessPage (3,250+ subscribers), the @gr8managerbot provisioning bot, and developer handle @greatnessmgr. Operator panel login requires a user ID plus a 9-character license key, and provisioned operator domains follow the format api-[token].[base-domain]. The dashboard offers campaign statistics, captured cookies, a victim heat map, and configuration of phishing domains, CAPTCHA type, background theme, and cookie save method, plus 11+ downloadable lure templates (AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer and variants) packaged as ZIPs containing pre-built HTML, PDF redirectors, SVGs, and letter templates.
Greatness's original and still-core capability is an adversary-in-the-middle (AiTM) proxy: the phishing kit and backend relay credentials and MFA challenges in real time to the legitimate Microsoft 365 login page, stealing usernames, passwords, and authenticated session cookies. The kit dynamically pulls the target organization's real logo and background from the Microsoft 365 login page to build convincing lures, and the API blocks unwanted IPs from viewing phishing pages to impede researchers and sandboxes. In 2026 the platform added OAuth 2.0 Device Authorization Grant phishing. This abuses the legitimate device code flow: the attacker's backend requests a device code from Microsoft's /oauth2/v2.0/devicecode endpoint using a legitimate first-party client ID, then social-engineers the victim into visiting the real microsoft.com/devicelogin page and entering the code. Because the page the user authenticates against really is Microsoft, there is no fake login site to detect; MFA is genuinely satisfied by the victim, and the resulting access token (60-90 min) and rolling refresh token (up to 90 days) are issued to the attacker's client. When the Microsoft Authentication Broker client ID is used, a single approval can yield rogue device registration and long-lived refresh tokens.
Campaigns attributed to the Greatness ecosystem (operators tracked by Microsoft as Storm-1295) use five-stage redirect chains with anti-analysis protections, User-Agent fingerprinting, and CAPTCHA gates before the victim reaches either the AiTM proxy or a device code endpoint. In an August 2026 campaign documented by ZeroBEC, spoofed RingCentral voicemail and performance-review emails sent from service@ringcentral.com landed in victim inboxes despite failing SPF, DKIM, and DMARC, because RingCentral sat on organizations' safe-sender allow lists — achieving a Spam Confidence Level (SCL) of -1 in Exchange. ZeroBEC links the campaign's targeting lists to the July 28, 2026 RingCentral data breach (claimed by ShinyHunters), noting that any vendor breach exposing a customer list simultaneously reveals which organizations likely whitelist that vendor's domain. Similar tradecraft is documented across the 2026 device-code phishing wave: dynamic device-code generation (the 15-minute code countdown starts only when the victim clicks), clipboard hijacking to copy the code, backend polling every 3-5 seconds, and multi-hop redirect chains through Vercel, Cloudflare Workers, and AWS Lambda. Backend token-harvesting infrastructure runs on Railway.com (PaaS), whose clean IP reputation and email-only signup made it attractive.
Post-compromise, harvested tokens are replayed within minutes from dedicated proxy/VPS infrastructure. One observed Greatness AiTM proxy IP (38.248.95.214) was still actively authenticating against a victim's Microsoft 365
Target sectors: manufacturing, health, technology, real-estate, construction, financial-services, legal, government administration, education, telecoms, energy, nonprofit
Target regions: united states of america, united kingdom, australia, canada, south africa, Europe, Middle East, North America, Asia
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1566.001, T1204.001, T1528, T1550.001, T1539, T1056.001, T1557, T1036, T1027