Greatness PhaaS Adds Device-Code MFA Bypass

The Hacker News · High sophistication
Last updated August 4, 2026

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step redirect chains with CAPTCHA and anti-analysis checks, ending at either an adversary-in-the-middle (AiTM) proxy or a device-code endpoint. Once attackers have tokens, they can quickly access Microsoft 365 data (Outlook, Teams, SharePoint, OneDrive) and maintain access for weeks.

Key findings

  • Greatness PhaaS now supports both AiTM token theft and device-code phishing from the same operator panel.
  • Campaigns include spoofed RingCentral voicemail lures that can reach inboxes by abusing “safe sender” exclusions even when SPF/DKIM/DMARC fail.
  • Victims are driven through a five-stage redirect chain with fingerprinting and a CAPTCHA gate before reaching either an AiTM proxy or a device-code endpoint.
  • Device-code phishing uses Microsoft’s legitimate device authorization flow, making the login page look real; the main clue is an unexpected short code and a reason to enter it.
  • After compromise, stolen tokens may be replayed within minutes and used to enumerate Microsoft 365 resources via Microsoft Graph; observed access sometimes persists for weeks.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT / Identity & Access Management, Microsoft 365 administrators, Helpdesk / Service Desk.
  • Affected industries: Any organization using Microsoft 365, Any organization using RingCentral, Business and professional services (general).
  • Attack channels: email, website.
  • Impersonated: RingCentral, Microsoft.

Awareness takeaways

  • Treat unexpected ‘device code’ prompts as suspicious, even if the page looks like real Microsoft.
  • Don’t rely on “safe sender”/allow-list trust for vendor emails; verify unexpected voicemail/document notifications through the vendor portal or known bookmark.
  • Assume a clicked phishing link may include multiple hidden redirects and CAPTCHA gates; users should stop and report if a simple task becomes a multi-step ‘verification’ journey.
  • Plan for fast attacker follow-on actions after a successful phish (minutes), including token replay and mailbox/Teams/SharePoint access; emphasize immediate reporting.

Red flags to watch for

  • Message lands in the inbox despite email authentication failures (SPF/DKIM/DMARC)
  • Unexpected prompt to enter a short device code for a normal activity like listening to voicemail
  • Link goes through multiple redirects and a CAPTCHA before showing the final page
  • Link routes through unusual redirect steps and CAPTCHA gates
  • Unexpected sign-in prompt for routine content access
  • Post-login account activity occurs quickly from unfamiliar infrastructure
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “New voicemail received (RingCentral), listen to message.” Looks normal, lands right in your inbox. You click. Now it’s a five-step maze: redirects, a CAPTCHA, then a real Microsoft page asking you to enter a short device code to hear the voicemail. This is the Greatness kit using Microsoft’s legit device-code flow. There’s nothing visually wrong. The only clue: you weren’t expecting a device code for a simple voicemail. If you ever see a surprise Microsoft device code prompt, stop. Don’t enter it, report the email or page to Security immediately.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Fake Cloudflare CAPTCHA Tricks Users Into Running Code

Fake Cloudflare CAPTCHA Tricks Users Into Running Code

A campaign dubbed “TerminalFix” uses compromised websites to display fake Cloudflare CAPTCHA checks that instruct visitors to copy and run a PowerShell command. The goal is to get a user to run attacker-provided commands themselves, which can lead to persistent access and deeper intrusion into the…

August 31, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
RingCentral Breach Fuels Spoofed M365 Phish Risk

RingCentral Breach Fuels Spoofed M365 Phish Risk

Have I Been Pwned says the RingCentral incident exposed 1.6 million email addresses plus names, phone numbers, and physical addresses, which can make targeted phishing more convincing. Separately, researchers described spoofed RingCentral emails that bypassed defenses due to allowlisting and led…

August 14, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026