The commercial phishing-as-a-service toolkit known as Greatness has recently expanded its capabilities to include device code phishing, a tactic that abuses the OAuth 2.0 Device Authorization Grant. This addition enables cybercriminals to bypass Multi-Factor Authentication and gain unauthorized access to user accounts. Greatness supports adversary-in-the-middle credential and token theft alongside device code phishing and OAuth consent abuse, all managed from a unified operator panel. Initially documented by Cisco Talos in May 2023, the platform targets Microsoft 365 business users and has been operational since mid-2022. Access to this toolkit is offered through a subscription model, with the price starting at $289 per month, an increase from $120 earlier in the year.

The Greatness platform offers a comprehensive operator dashboard that includes features such as campaign statistics, domain configuration, CAPTCHA selection, and downloadable phishing lure templates. It also supports multiple target platforms, including iCloud, Yahoo, and Google Workspace. Cybercriminals using this service can deploy phishing campaigns with templates ranging from voicemail to document sharing, all designed to lower the entry barrier for cybercrime. The phishing emails associated with this toolkit implement advanced anti-analysis protections and User-Agent fingerprinting, using a five-stage redirect chain to obscure their activities.

Recent campaigns leveraging Greatness have exploited trust configurations, such as impersonating RingCentral, to bypass email gateways and reach the victim's inbox. These attacks take advantage of safe sender exclusions to avoid detection, even when failing SPF, DKIM, and DMARC checks. Post-compromise, threat actors quickly replay harvested authentication tokens from proxy infrastructure and enumerate victim resources through the Microsoft Graph API. This persistent access allows for long-term infiltration, with the attackers registering new devices and setting up malicious inbox rules to maintain their foothold. As phishing remains a primary access vector, the evolution of PhaaS platforms like Greatness poses increasing challenges for cybersecurity defenses.