Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

A sophisticated phishing attack has emerged, exploiting a previously unknown vulnerability in device code systems to bypass multi-factor authentication (MFA) and steal sensitive tokens. The attackers’ method, dubbed “Device Code PhaaS,” uses a novel approach to deceive users into divulging their login credentials.

Greatness PhaaS, a group of experienced threat actors, has been actively using this technique to compromise high-profile targets worldwide. By exploiting the device code system’s vulnerability, they can bypass MFA and gain unauthorized access to sensitive areas of compromised systems. The attack involves creating a fake device code prompt that mimics the real thing, but instead of verifying the user’s credentials, it extracts their login information.

This technique is particularly insidious because it takes advantage of the way device codes work. Normally, when users attempt to log in to an account, they’re prompted with a one-time device code that they enter along with their password and other security measures. However, Greatness PhaaS has figured out how to manipulate this system by creating fake prompts that prompt users for their login credentials under the guise of authenticating the device.

This phishing technique is particularly effective because it doesn’t rely on social engineering tactics like sending malicious emails or messages. Instead, it exploits a vulnerability in the device code system itself, making it much harder for security software to detect. Moreover, since MFA is bypassed, users may not even realize they’ve been compromised until it’s too late.

The impact of this attack extends beyond individual users to entire organizations that rely on secure authentication protocols. The ability to steal sensitive tokens and gain access to high-security areas can have far-reaching consequences, including data breaches, financial losses, and reputational damage.

In a world where security threats are constantly evolving, it’s essential for individuals and organizations to stay vigilant and adapt their defenses accordingly. One practical takeaway from this incident is the importance of monitoring device code prompts carefully, especially when entering sensitive information. Users should be aware that even seemingly innocuous prompts can be designed to deceive and extract login credentials.


Source: The Hacker News — 2026-08-04