Utopia Tech
SecurityAI-assisted1 min read

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness phishing-as-a-service (PhaaS) platform has integrated device code phishing capabilities, exploiting OAuth 2.0 Device Authorization Grant protocols to circumvent multi-factor authentication protections. This enhancement allows threat actors to conduct adversary-in-the-middle attacks that steal credentials and session tokens, representing an escalation in commercially available cybercr

UT

Utopia Tech

August 4, 2026 · 1 min read

Share

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content