Popular Phishing Toolkit Now Bypasses MFA Using a New Trick
A widely used phishing-as-a-service (PhaaS) toolkit called Greatness has added a new attack method known as device code phishing. This technique abuses a legitimate Microsoft sign-in feature called OAuth 2.0 Device Authorization Grant, which is normally used to let devices like smart TVs or printers log into accounts without typing a password directly on them.
Attackers trick victims into entering a code on a real Microsoft login page, which then hands the attacker a valid access token — effectively bypassing multi-factor authentication (MFA) entirely, since the victim unknowingly authorises the attacker's session. Combined with Greatness' existing adversary-in-the-middle (AiTM) credential theft capabilities, this makes the toolkit significantly more dangerous, as it can now defeat one of the most common security protections businesses rely on.
Because device code phishing exploits a real, legitimate authentication flow rather than a fake login page, it can be harder for employees and even some security tools to detect. As phishing-as-a-service kits become more sophisticated and accessible to less skilled criminals, small businesses relying solely on MFA for account protection should be aware that determined attackers now have tools to work around it.