Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.

“Greatness supports AiTM [adversary-in-the-middle] credential and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called

Daisugi the Japanese Technique of Trees Out of Trees, Making Exact Straight Wood

Daisugi the Japanese Technique of Trees Out of Trees, Making Exact Straight Wood Source: Hacker News

The bottleneck might be the air in the room

The bottleneck might be the air in the room Source: Hacker News