Greatness phishing service adds device code attacks and broader token theft

The Greatness phishing-as-a-service platform has added device code phishing to an operator panel that already supports adversary-in-the-middle token theft and OAuth consent abuse. ZeroBEC said the service targets platforms including Microsoft 365, iCloud, Yahoo and Google Workspace, while subscriptions advertised through Telegram now start at $289 per month.
Greatness has targeted Microsoft 365 business users since at least mid-2022 and was publicly documented by Cisco Talos in May 2023. Its public Telegram channel has more than 3,250 subscribers and distributes announcements and feature updates. Access includes campaign statistics, domain and CAPTCHA configuration, and more than 11 downloadable lure templates.
How the device code branch works
Victims who follow a malicious email link pass through a five-stage redirect chain with anti-analysis checks, User-Agent fingerprinting and a CAPTCHA gate. The final destination can be an adversary-in-the-middle proxy or a device code endpoint.
The newer branch abuses the legitimate OAuth 2.0 Device Authorization Grant. Instead of presenting an obviously fake sign-in page, the attacker gives the victim a short code and a plausible reason to enter it on Microsoft's genuine page. The resulting authorization lets the operator obtain tokens without building a conventional counterfeit login site.
The platform also supplies packaged lures such as AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR and VideoPlayer. Their ZIP files contain pre-built HTML, PDF redirectors, SVG files and letter templates, reducing the work required to launch a campaign.
Trusted vendors and persistent access
Recent campaigns used spoofed RingCentral voicemail messages that reached legitimate customers despite failing SPF, DKIM and DMARC checks. ZeroBEC said safe-sender exclusions created for the real vendor allowed the messages through, showing how customer relationships and email trust settings can become part of the attack path.
This reliance on trusted accounts and infrastructure also reflects recent analysis of trusted-account phishing chains, where compromised relationships and layered delivery chains complicate detection beyond the initial lure.
After compromise, harvested tokens were replayed within minutes through dedicated proxy infrastructure. Attackers then enumerated Outlook, Teams, SharePoint, Exchange, OneDrive, contacts, calendars and registered applications through the Microsoft Graph API. ZeroBEC observed one proxy address authenticating to a victim account more than two weeks after the original campaign.
Microsoft has also recorded attackers registering devices shortly after a breach to generate a Primary Refresh Token, then delaying malicious inbox rules or email theft for several hours. Those pauses can reduce the chance of immediate detection while preserving longer-term access.
What organizations should change
Defenders can block device code authentication globally through Conditional Access Policies and move users to phishing-resistant MFA. Where the flow is essential, LevelBlue recommends explicitly excluding only the required users or resources, continuously auditing usage and revoking access when it is no longer necessary.
Businesses should also train employees to distrust unexpected codes and treat vendor breach notices as a reason to review safe-sender exclusions. The practical priority is to restrict an authentication flow that most users do not need, while tightening the trust rules that allow convincing vendor-themed messages to bypass normal controls.

