Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targeting cloud accounts. The service now combines AiTM credential theft, OAuth consent abuse, and multiple target platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace. That shift lowers the barrier to entry for affiliates and increases the scale and persistence of account compromise.
Related Happenings
Tycoon2FA-Kali365-ARToken alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score89
First: 31.07.2026 14:24
Last: 31.07.2026 14:24
Sources 1
About this happening:
Phishing-as-a-service kits have turned device code phishing into a commoditized feature, expanding token theft across multiple criminal platforms and accelerating oper...
Tycoon2FA-Kali365-ARToken alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Phishing-as-a-service kits have turned device code phishing into a commoditized feature, expanding token theft across multiple criminal platforms and accelerating oper...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Timeline
-
04.08.2026 20:27 2 articles · 3h ago
Greatness adds device code phishing to its operator panel
Initial DisclosureGreatness added device code phishing to its phishing-as-a-service toolkit, pairing the OAuth 2.0 Device Authorization Grant with existing AiTM token theft and OAuth consent abuse capabilities to bypass MFA and steal session tokens. The service is marketed through a public Telegram channel and bot-based registration flow, and recent campaigns used spoofed RingCentral voicemail lures plus post-compromise token replay against Microsoft 365 resources such as Outlook, Teams, SharePoint, Exchange, and OneDrive.
Show sources
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens — thehackernews.com — 04.08.2026 20:27
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens — thehackernews.com — 04.08.2026 20:27