Greatness PhaaS Adds Device-Code MFA Bypass

The Hacker News · High sophistication
Last updated August 4, 2026

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step redirect chains with CAPTCHA and anti-analysis checks, ending at either an adversary-in-the-middle (AiTM) proxy or a device-code endpoint. Once attackers have tokens, they can quickly access Microsoft 365 data (Outlook, Teams, SharePoint, OneDrive) and maintain access for weeks.

Key findings

  • Greatness PhaaS now supports both AiTM token theft and device-code phishing from the same operator panel.
  • Campaigns include spoofed RingCentral voicemail lures that can reach inboxes by abusing “safe sender” exclusions even when SPF/DKIM/DMARC fail.
  • Victims are driven through a five-stage redirect chain with fingerprinting and a CAPTCHA gate before reaching either an AiTM proxy or a device-code endpoint.
  • Device-code phishing uses Microsoft’s legitimate device authorization flow, making the login page look real; the main clue is an unexpected short code and a reason to enter it.
  • After compromise, stolen tokens may be replayed within minutes and used to enumerate Microsoft 365 resources via Microsoft Graph; observed access sometimes persists for weeks.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT / Identity & Access Management, Microsoft 365 administrators, Helpdesk / Service Desk.
  • Affected industries: Any organization using Microsoft 365, Any organization using RingCentral, Business and professional services (general).
  • Attack channels: email, website.
  • Impersonated: RingCentral, Microsoft.

Awareness takeaways

  • Treat unexpected ‘device code’ prompts as suspicious, even if the page looks like real Microsoft.
  • Don’t rely on “safe sender”/allow-list trust for vendor emails; verify unexpected voicemail/document notifications through the vendor portal or known bookmark.
  • Assume a clicked phishing link may include multiple hidden redirects and CAPTCHA gates; users should stop and report if a simple task becomes a multi-step ‘verification’ journey.
  • Plan for fast attacker follow-on actions after a successful phish (minutes), including token replay and mailbox/Teams/SharePoint access; emphasize immediate reporting.

Red flags to watch for

  • Message lands in the inbox despite email authentication failures (SPF/DKIM/DMARC)
  • Unexpected prompt to enter a short device code for a normal activity like listening to voicemail
  • Link goes through multiple redirects and a CAPTCHA before showing the final page
  • Link routes through unusual redirect steps and CAPTCHA gates
  • Unexpected sign-in prompt for routine content access
  • Post-login account activity occurs quickly from unfamiliar infrastructure
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “New voicemail received (RingCentral), listen to message.” Looks normal, lands right in your inbox. You click. Now it’s a five-step maze: redirects, a CAPTCHA, then a real Microsoft page asking you to enter a short device code to hear the voicemail. This is the Greatness kit using Microsoft’s legit device-code flow. There’s nothing visually wrong. The only clue: you weren’t expecting a device code for a simple voicemail. If you ever see a surprise Microsoft device code prompt, stop. Don’t enter it, report the email or page to Security immediately.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Hacked Wi‑Fi Portals Steal M365 Logins

Hacked Wi‑Fi Portals Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where attackers tampered with public Wi‑Fi captive portal networks (hotels/conference venues) to redirect users to attacker-controlled pages. The goal was to steal Microsoft 365 credentials (and sometimes deliver malware) by using…

August 3, 2026
Teams HR Phish Used Real Microsoft Login Flow

Teams HR Phish Used Real Microsoft Login Flow

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When victims approved the requested permissions, the attackers obtained an authorization token and could access Microsoft 365 data like Outlook,…

July 30, 2026
M365 Device Code Phishing Bypasses User Suspicion

M365 Device Code Phishing Bypasses User Suspicion

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue login tokens directly to the attacker. Because the victim completes a legitimate MFA-approved sign-in on a legitimate Microsoft URL, the…

July 21, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 is a phishing kit that abuses Microsoft’s real “device code” sign-in flow to trick employees into approving attacker-controlled login codes. Once a victim completes authentication on Microsoft’s legitimate page, attackers can receive access and refresh tokens that may grant ongoing access…

August 5, 2026