Greatness is a PhaaS solution that has been stolen by hackers and is now being sold on the dark web. The tool has been used to target organizations that use 2FA, including Microsoft and Google. The Greatness PhaaS has been estimated to have affected over 1 million users, making it a significant threat to organizations that use MFA.
Device code phishing is a highly effective method for bypassing MFA, as it exploits the legitimate OAuth 2.0 Device Authorization Grant to trick users into divulging sensitive information. This technique has been used to steal tokens, login credentials, and other sensitive data from organizations that use 2FA. Greatness is just one of several PhaaS solutions that are using this technique to target organizations.
Other tools, such as Cobalt Strike and Spear Phishing Kit, have also been known to use device code phishing to bypass MFA and steal sensitive data. The lack of awareness and education about the threat of device code phishing is a major concern for organizations that use 2FA. Many organizations are not aware that device code phishing is a real threat, and are therefore not taking adequate measures to protect themselves.
Security experts recommend that organizations take several steps to protect themselves, including implementing robust security measures, educating employees on the threat of device code phishing,