# Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens

> The commercial Greatness phishing-as-a-service (PhaaS) toolkit now supports OAuth 2.0 Device Authorization Grant (device code) phishing, letting affiliates silently obtain authentication tokens that bypass MFA. Distributed via Telegram (3,250+ subscribers, $289/month), Greatness chains AiTM credential/session-cookie theft, device code phishing, and OAuth consent abuse against Microsoft 365 environments, with post-compromise persistence via Primary Refresh Token (PRT) generation and rogue device registration within minutes of breach.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1873
- **ID:** TL-2026-1873
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Greatness PhaaS Operators
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Greatness is a commercial phishing-as-a-service toolkit first publicly documented by Cisco Talos in May 2023 and active since at least mid-2022, exclusively (and later primarily) targeting Microsoft 365 business users. The platform combines a phishing kit, a backend service API, and Telegram bot integration into a turnkey credential theft service. Affiliates pay a $289/month subscription (up from $120/month in January 2024), and access is brokered through the public Telegram channel @GreatnessPage (3,250+ subscribers), the @gr8managerbot provisioning bot, and developer handle @greatnessmgr. Operator panel login requires a user ID plus a 9-character license key, and provisioned operator domains follow the format api-[token].[base-domain]. The dashboard offers campaign statistics, captured cookies, a victim heat map, and configuration of phishing domains, CAPTCHA type, background theme, and cookie save method, plus 11+ downloadable lure templates (AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer and variants) packaged as ZIPs containing pre-built HTML, PDF redirectors, SVGs, and letter templates.

Greatness's original and still-core capability is an adversary-in-the-middle (AiTM) proxy: the phishing kit and backend relay credentials and MFA challenges in real time to the legitimate Microsoft 365 login page, stealing usernames, passwords, and authenticated session cookies. The kit dynamically pulls the target organization's real logo and background from the Microsoft 365 login page to build convincing lures, and the API blocks unwanted IPs from viewing phishing pages to impede researchers and sandboxes. In 2026 the platform added OAuth 2.0 Device Authorization Grant phishing. This abuses the legitimate device code flow: the attacker's backend requests a device code from Microsoft's /oauth2/v2.0/devicecode endpoint using a legitimate first-party client ID, then social-engineers the victim into visiting the real microsoft.com/devicelogin page and entering the code. Because the page the user authenticates against really is Microsoft, there is no fake login site to detect; MFA is genuinely satisfied by the victim, and the resulting access token (60-90 min) and rolling refresh token (up to 90 days) are issued to the attacker's client. When the Microsoft Authentication Broker client ID is used, a single approval can yield rogue device registration and long-lived refresh tokens.

Campaigns attributed to the Greatness ecosystem (operators tracked by Microsoft as Storm-1295) use five-stage redirect chains with anti-analysis protections, User-Agent fingerprinting, and CAPTCHA gates before the victim reaches either the AiTM proxy or a device code endpoint. In an August 2026 campaign documented by ZeroBEC, spoofed RingCentral voicemail and performance-review emails sent from service@ringcentral.com landed in victim inboxes despite failing SPF, DKIM, and DMARC, because RingCentral sat on organizations' safe-sender allow lists — achieving a Spam Confidence Level (SCL) of -1 in Exchange. ZeroBEC links the campaign's targeting lists to the July 28, 2026 RingCentral data breach (claimed by ShinyHunters), noting that any vendor breach exposing a customer list simultaneously reveals which organizations likely whitelist that vendor's domain. Similar tradecraft is documented across the 2026 device-code phishing wave: dynamic device-code generation (the 15-minute code countdown starts only when the victim clicks), clipboard hijacking to copy the code, backend polling every 3-5 seconds, and multi-hop redirect chains through Vercel, Cloudflare Workers, and AWS Lambda. Backend token-harvesting infrastructure runs on Railway.com (PaaS), whose clean IP reputation and email-only signup made it attractive.

Post-compromise, harvested tokens are replayed within minutes from dedicated proxy/VPS infrastructure. One observed Greatness AiTM proxy IP (38.248.95.214) was still actively authenticating against a victim's Microsoft 365 account more than two weeks after the initial phishing campaign, demonstrating the prolonged validity of stolen refresh tokens. Attackers enumerate victim M365 resources — Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars, and registered applications — via the Microsoft Graph API, and register new devices within minutes of a breach to generate a Primary Refresh Token (PRT) for long-term persistence. They commonly wait several hours before creating malicious inbox rules or exfiltrating sensitive email to avoid detection, and in financial-exfiltration variants search mail for wire-transfer details, pending invoices, and executive correspondence. Related device-code PhaaS kits — EvilTokens (advertised February 2026, whose backend was assessed as likely AI-generated, with endpoints for PRT conversion, OWA session cookies, and parallel Graph reconnaissance) and Tycoon 2FA operators who dispersed to device-code flows after a March 2026 Europol-led takedown of 330 domains — show the technique becoming a productized cybercrime service.

The attack is not a product vulnerability: Microsoft explicitly notes that device code phishing exploits an industry-standard authentication flow whose session is not strongly bound to the original requester, and that no defect enables it. Defensive guidance centers on blocking the device code authentication method in Conditional Access, moving to phishing-resistant MFA, auditing safe-sender lists, revoking tokens via revokeSignInSessions and disabling accounts (access tokens can remain valid ~1 hour after revocation unless Continuous Access Evaluation is enabled), restricting device registration, and hunting for the documented sign-in indicators (ErrorCode 50199 followed by 0, anonymous-IP and threat-intelligence risk events, and new device registrations correlated with token activity).

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1566.001 Spearphishing Attachment
- T1204.001 Malicious Link
- T1528 Steal Application Access Token
- T1550.001 Application Access Token
- T1539 Steal Web Session Cookie
- T1056.001 Keylogging
- T1557 Adversary-in-the-Middle
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1685 Disable or Modify Tools
- T1087.004 Cloud Account
- T1069.003 Cloud Groups
- T1114.002 Remote Email Collection
- T1530 Data from Cloud Storage
- T1098.005 Device Registration
- T1090 Proxy
- T1567.002 Exfiltration to Cloud Storage

## Sources

- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens](https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html)
- [ZeroBEC — Greatness PhaaS: AiTM and Device Code Phishing Analysis](https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing)
- [Microsoft Security Blog — Inside an AI-Enabled Device Code Phishing Campaign](https://www.microsoft.com/en-us/security/blog/2026/04/ai-enabled-device-code-phishing-campaign-april-2026)
- [Microsoft — Storm-2372 Conducts Device Code Phishing Campaign](https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/)
- [Cisco Talos — New Phishing-as-a-Service Tool 'Greatness' Already Seen in the Wild](https://blog.talosintelligence.com/new-phishing-as-a-service-tool-greatness-already-seen-in-the-wild/)
- [Huntress — Riding the Rails: Threat Actors Abuse Railway.com PaaS](https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign)
- [Sekoia — New Widespread EvilTokens Kit: Device Code Phishing as-a-Service (Part 1)](https://www.sekoia.com/blog/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1)
- [Okta Threat Intelligence — Tycoon 2FA Phishing Actors Disperse, Branch Into New Attacks](https://www.okta.com/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/)
- [eSentire TRU — Tycoon 2FA Operators Adopt OAuth Device Code Phishing](https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing)
- [Trend Micro — Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass](https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html)
- [LevelBlue — Go With the Flow: Abusing OAuth Device Code Flow](https://www.levelblue.com/blogs/security-essentials/go-with-the-flow-abusing-oauth-device-code-flow)
- [Trellix — Tale of Greatness: Journey Through Dark Roads](https://www.trellix.com/blogs/research/tale-of-greatness-journey-through-dark-roads/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1873
