Summary
- ZeroBEC research indicates Greatness now combines adversary-in-the-middle phishing, device-code abuse, and malicious OAuth consent.
- Device-code attacks use Microsoft’s legitimate sign-in process to obtain tokens without requiring a counterfeit password page.
- Victim numbers and the extent to which the latest capabilities are being used operationally remain unknown.
The Greatness phishing-as-a-service platform has added device-code phishing and malicious OAuth-consent workflows, extending a criminal service previously associated with Microsoft 365 credential theft into attacks centred on access tokens and legitimate authentication processes.
ZeroBEC researchers found that the platform now brings adversary-in-the-middle phishing, device-code attacks, OAuth consent abuse, and support for several target services into the same operator panel and backend infrastructure.
Greatness has been active since at least 2022 and became known for highly tailored Microsoft 365 login pages. Earlier versions could pre-populate a victim’s email address, reproduce the branding of the targeted organisation, and operate as an adversary-in-the-middle service to intercept credentials, multifactor authentication responses, and authenticated session cookies.
The latest expansion adds another route into cloud identities. Microsoft’s device-code authentication flow is designed for equipment that cannot easily display or operate a conventional browser, such as televisions, command-line tools, or input-constrained devices.
In a malicious use of the process, the attacker initiates an authentication request and receives a short device code. The victim is persuaded to visit Microsoft’s legitimate device-login page, enter the code, and complete authentication. The victim is not necessarily giving a password to a fake site; instead, the user is authorising the attacker-controlled session.
Multifactor authentication may still occur and succeed during that process. Describing the technique only as an MFA bypass can therefore obscure the control failure. The authentication factor is accepted, but it is applied to an authorisation request initiated by the attacker rather than to activity the user intended to approve.
Once issued, access and refresh tokens may allow the attacker to reach Microsoft 365 services without repeatedly presenting the password. Depending on the permissions and session conditions, that access can extend to email, collaboration data, files, contacts, and other services attached to the identity.
ZeroBEC also reported that Greatness supports OAuth consent abuse. That technique attempts to persuade a user or administrator to grant permissions to an attacker-controlled application. The resulting access is tied to an authorised application identity and may survive a password reset unless the consent, application, tokens, and associated sessions are revoked.
The platform is also reported to support targets beyond Microsoft 365, including iCloud, Yahoo, and Google Workspace. Researchers observed RingCentral-themed lures used to direct victims into Microsoft account compromise, although the presence of a copied brand does not indicate that RingCentral’s own systems were breached.
Device-code attacks have expanded across several criminal phishing services during 2026. Microsoft, Proofpoint, Huntress, and other researchers have documented campaigns that use genuine authentication pages, disposable hosting, and token replay rather than relying entirely on counterfeit login forms.
That shift changes what appears suspicious during an incident. A password may not have been submitted to an attacker, the authentication page may belong to Microsoft, and the user may have completed a legitimate multifactor prompt. The abnormal elements sit around the transaction: who initiated the code, where the resulting sign-in originates, which application receives access, and whether the activity fits the user’s role.
The commercial packaging of several techniques in one service also reduces the distinction between individual phishing methods. Operators can change lures or authentication routes while retaining the same customer panel, victim tracking, token handling, and backend infrastructure.
No affected organisation has publicly confirmed a breach linked to the latest Greatness capabilities, and the service’s current operational reach is not established. Victim numbers, customer activity, and the proportion of successful compromises remain unknown.




