Greatness: the phishing kit as a service that steals tokens with device code phishing and redefines corporate security

Author: Published 5 min de lectura 190 reading

The images in this article were generated with artificial intelligence. How we publish

The ecosystem of cybercrime advances quickly and a new chapter is written by the marketing of sophisticated techniques to avoid security controls: the phishing- as- a- service kit (PhaaS) known as Greatness has added support for the so-called "device code phishing," a variant that abuses the legitimate flow OAuth 2.0 Device Authorization Grant to capture tokens and remove traditional authentication factors. The novelty is not only technical, but commercial: services like this pack complexity and sell it by subscription, drastically reducing the barrier for low-skilled attackers to achieve serious business impacts.

In practical terms, device code phishing takes advantage of a mechanism designed for devices with limited input: the service presents the user with a legitimate page of the identity provider and asks him to enter a short code into another device. The deception works because the authentication page is authentic, but the attacker controls the flow that associates that code to the session of the victim. The result is that the attacker gets valid tokens without the victim being in front of a false login website, which makes it difficult for users to detect and for surface mail and navigation controls. Microsoft maintains technical documentation of the device flow that explains how the grant works and why it can be used in this way: OAuth 2.0 Device Authorization Grant (Microsoft).

Greatness: the phishing kit as a service that steals tokens with device code phishing and redefines corporate security
Image generated with IA.

The convergence of tools - AiTM (adverse-in-the-middle), proxies for cookie theft, preconstructed templates for post and redirection chains with anti-analysis protections - turns platforms like Greatness into attack ecosystems. This professionalization results in more efficient campaigns: from initial delivery through lures that take advantage of safe shipping lists to the exploitation of tokens to explore and exfilter data via Microsoft GraphAPI. In addition, the prolonged validity of some tokens and the ability to generate Primary Refresh Tokens (PRT) for persistence increase the risk of sustained commitment.

A worrying vector identified in recent campaigns is the exploitation of existing confidence configurations with legitimate suppliers (e.g. RingCentral). If an organization has a domain in its list of safe senders for being a customer of a service, a supplier leak can become a guide for attackers who know exactly which domains will avoid filters. This requires rethinking the practice of automatic white lists: after a third-party gap, the exclusion configurations must be reviewed and hardened immediately.

The operational implications are clear: phishing remains the main entrance door and, thanks to PhaaS, attacks scale in volume and sophistication without necessarily increasing the attacker's expertise. This requires a change of strategy that combines technical prevention, tuned detection and human risk control. At the identity level, a critical lever is access policy: to block the overall use of the device grant or to restrict its application through conditional Access policies reduces the abuse area. Microsoft offers guides to design conditional access policies to control these types of flows: Overview of Conditional Access (Microsoft).

In addition to adjusting policies, it is essential to migrate to authentication methods phishing resistant such as FIDO2 keys or hardware-based certificates, and remove as far as possible MFAs that depend on single-use codes entered manually or approval requests in applications that can be simulated or intercepted. Staff training should focus on a specific point: distrust of unexpected codes and non-context reauthentication requests. The combination of technical controls and awareness-raising drastically reduces the effectiveness of campaigns based on social engineering.

In detection and response it is appropriate to pay attention to early signals: authentication by device flows in accounts that should not be used, emergence of new registered devices (possible generation of PRT), abnormal use of the Microsoft GraphAPI, late creation of entry tray rules and access from proxy infrastructure that repeat login minutes or hours after a campaign. Instrument alerts and playbooks for credentials rotation, tokens revocation and suspicious session blocking shortens the attack window and limits damage.

Greatness: the phishing kit as a service that steals tokens with device code phishing and redefines corporate security
Image generated with IA.

The threat also has an organizational hygiene dimension: imposing strict DMARC, SPF and DKIM policies is not enough when safe shipping lists remain unreviewed. After each notification of a supplier's commitment, organisations should audit the exclusion of gateway and validate that there are no alternative routes for phishing delivery. The practical guides of agencies like CISA on how to protect against phishing remain a useful starting point for security teams and IT officials: Tips to protect against phishing (CISA).

Finally, we must not lose sight of the crime economy: access to preconfigured panels, Telegram support and ready-to-use templates makes security a continuous race. Internal infrastructure must assume that the next campaign will come and prepare controls that do not only depend on users "not falling" into deception. Periodic audits of permits, reduced privileges, segmentation of access and automatic revocation policies when detecting abnormal behavior are measures that, combined with phishing-resistant authentication and an active response posture, may undermine the effectiveness of services such as Greatness.

In short, the evolution of phishing kits to integrated token theft platforms requires a coordinated response: limit and audit the use of the device code grant, adopt phishing-proof MFA, tighten mail exclusions after third-party gaps, and improve the detection of the abnormal use of tokens. Effective defense is no longer optional: it is the condition for organizations to maintain control of their identities and assets in the cloud.

Coverage

Related

More news on the same subject.