Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

A new phishing campaign has emerged, leveraging a sophisticated technique called device code phishing (DCP) to bypass multi-factor authentication (MFA) and steal tokens. Greatness PhaaS, a notorious threat actor, is behind this latest scheme, targeting organizations that rely on MFA as an additional security layer.

Greatness PhaaS has been making headlines in recent months for its innovative attacks, which often exploit vulnerabilities in the way organizations implement MFA. In this case, the group has developed a device code phishing module that can intercept and manipulate verification codes sent to users’ devices via SMS or authenticator apps. By doing so, the attackers can bypass even the most robust MFA systems, allowing them to gain unauthorized access to sensitive areas of the targeted network.

The modus operandi behind this attack is relatively straightforward: an attacker sends a phishing email to a victim’s inbox, which contains a link to a malicious website. The site then requests permission to access the device’s camera and microphone, ostensibly for security reasons. Once granted, the attackers use these permissions to inject malware onto the user’s device, allowing them to intercept verification codes sent via SMS or authenticator apps. These codes are then used to authenticate with MFA-enabled systems, effectively bypassing the additional security layer.

The affected organizations are numerous and diverse, ranging from small businesses to large enterprises in various industries. What’s concerning is that these attacks can be highly targeted, often focusing on specific individuals within an organization who have access to sensitive data or systems. This level of precision suggests that Greatness PhaaS may have obtained insider knowledge or been able to gather intelligence through social engineering tactics.

The implications of this attack are far-reaching and significant. If left unchecked, attackers could potentially gain access to entire networks, leading to catastrophic consequences for organizations and their customers. Furthermore, the use of device code phishing highlights a critical vulnerability in MFA systems: the assumption that users will always interact with verification codes on trusted devices.

As a result, it’s essential for organizations to reassess their MFA implementation and consider additional security measures to mitigate the risk of device code phishing. This includes regularly updating software and browsers, implementing strict access controls, and monitoring user behavior for signs of suspicious activity. Moreover, users should remain vigilant when interacting with verification codes on public or untrusted devices, as even a seemingly innocuous action can have devastating consequences in the wrong hands.


Source: The Hacker News — 2026-08-04