Particle.news
Download on the App Store

Greatness PhaaS Uses Device‑Code Phishing and AiTM Proxies to Steal Microsoft 365 Tokens

Researchers warn the platform’s new OAuth flows let attackers bypass multi‑factor authentication to gain long‑lived access to corporate Microsoft 365 accounts.

Overview

  • This week ZeroBEC and other researchers reported that Greatness, a commercial phishing‑as‑a‑service toolkit, now bundles adversary‑in‑the‑middle (AiTM) proxying, OAuth consent abuse, and the OAuth 2.0 device‑code flow into a single operator panel.
  • The device‑code technique shows a short numeric code on a genuine identity provider page so victims enter it without seeing a fake login, which lets attackers obtain MFA‑approved tokens silently.
  • Operators have spoofed RingCentral voicemail lures and used safe‑sender whitelist tricks after RingCentral’s July 28 breach to get phishing emails past filters and into business inboxes.
  • After compromise attackers immediately replay harvested tokens from proxy or VPS IPs to call the Microsoft Graph API and enumerate Outlook, Teams, SharePoint, OneDrive and other tenant data, with access lasting days or more than two weeks in observed cases.
  • Defenders are urged to audit safe‑sender lists, revoke and refresh OAuth consents and refresh tokens, hunt for suspicious MFA approvals from hosting IPs, block or tightly scope the device‑code flow with Conditional Access, and adopt phishing‑resistant MFA.