Overview
- This week ZeroBEC and other researchers reported that Greatness, a commercial phishing‑as‑a‑service toolkit, now bundles adversary‑in‑the‑middle (AiTM) proxying, OAuth consent abuse, and the OAuth 2.0 device‑code flow into a single operator panel.
- The device‑code technique shows a short numeric code on a genuine identity provider page so victims enter it without seeing a fake login, which lets attackers obtain MFA‑approved tokens silently.
- Operators have spoofed RingCentral voicemail lures and used safe‑sender whitelist tricks after RingCentral’s July 28 breach to get phishing emails past filters and into business inboxes.
- After compromise attackers immediately replay harvested tokens from proxy or VPS IPs to call the Microsoft Graph API and enumerate Outlook, Teams, SharePoint, OneDrive and other tenant data, with access lasting days or more than two weeks in observed cases.
- Defenders are urged to audit safe‑sender lists, revoke and refresh OAuth consents and refresh tokens, hunt for suspicious MFA approvals from hosting IPs, block or tightly scope the device‑code flow with Conditional Access, and adopt phishing‑resistant MFA.