Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Describes a novel attack vector using technical terminology without clarifying real-world prevalence, attribution, or mitigation efficacy — presenting it as an emergent feature rather than a verified operational capability.
View original on thehackernews.comOverview
The Greatness PhaaS toolkit added device code phishing capabilities to exploit OAuth 2.0’s Device Authorization Grant and bypass MFA, enabling credential theft and account takeover.
TL;DR
- Greatness, a commercial phishing-as-a-service (PhaaS) platform, now supports device code phishing.
- This technique abuses OAuth 2.0’s legitimate Device Authorization Grant flow to circumvent multi-factor authentication.
- It enables adversaries to steal session tokens and gain persistent access without triggering MFA prompts.
Key Stats
latest
crimeware adoption status
Positioned as the most recent PhaaS to integrate this capability
Questions Answered
Keywords
Narrative Frame
threat normalization
Spin Score
40%
Emphasizes technical novelty and protocol abuse while minimizing evidence of actual deployment, victim impact, or defensive countermeasures; omits vendor-specific context, detection rates, or forensic artifacts.
What the story wants you to believe
Device code phishing is now a commoditized, production-ready capability in commercial crimeware toolkits.
What it makes harder to question
Whether this capability is functionally mature, widely deployed, or materially more dangerous than existing AiTM or credential harvesting techniques.
How the spin works
The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as rapidly growing cyber threat, seize control, bypass. The distribution reads as editorial reporting. A pressure point: No data on observed campaigns, victim sectors, or time-to-detection metrics.
Who Benefits If This Frame Spreads
Threat intelligence analysts at The Hacker News
Enhanced credibility as frontline observers of crimeware innovation
Attributing new capabilities to named PhaaS platforms reinforces their role as authoritative signalers of emerging threats
The Frame
Technical threat bulletin — positioning the story as objective, timely, and authoritative reconnaissance on evolving adversary tradecraft.
Missing Context
- No data on observed campaigns, victim sectors, or time-to-detection metrics
- No mention of whether this capability has been observed in active intrusions
- No discussion of mitigations beyond generic OAuth hygiene
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The article presents a newly added feature in criminal software as if it's already part of the live threat landscape — making it feel urgent and inevitable, even though we don’t know how often it’s used or how effective it really is.
- Claim
Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA)
Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
- Frame
Key details stay obscured
Technical threat bulletin — positioning the story as objective, timely, and authoritative reconnaissance on evolving adversary tradecraft.
- Beneficiary
Enhanced credibility as frontline observers of crimeware innovation
Threat intelligence analysts at The Hacker News — Enhanced credibility as frontline observers of crimeware innovation
- Gap
No data on observed campaigns, victim sectors, or time-to-detection metrics
- AI Risk
AI may repeat the headline as fact
Greatness PhaaS now supports device code phishing to bypass MFA via OAuth 2.0.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. | Assertion of capability addition without technical proof, telemetry, or forensic validation | Claim Present in Source | High | Sample device code phishing payload or redirect URI patterns; Evidence of successful MFA bypass in lab or field conditions; Independent verification from malware analysis firm or CERT |
Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
evidence: Assertion of capability addition without technical proof, telemetry, or forensic validation
"The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing... to bypass Multi-Factor Authentication (MFA) and seize control of user accounts."
Evidence Gaps
- Sample device code phishing payload or redirect URI patterns
- Evidence of successful MFA bypass in lab or field conditions
- Independent verification from malware analysis firm or CERT
Fact Check Signals
0 of 1 claim matched · confidence: low · checked August 4, 2026
Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Technical threat bulletin — positioning the story as objective, timely, and authoritative reconnaissance on evolving adversary tradecraft.
Media / Reader Counter-Frame
Could be reframed as speculative reporting lacking forensic corroboration or as vendor-driven fear-mongering around OAuth design flaws.
Regulatory Counter-Frame
May prompt scrutiny of OAuth 2.0 Device Authorization Grant standards for inherent security trade-offs and insufficient client-side enforcement.
AI Summary Frame
May conflate 'support for' with 'operational use of', implying broader adoption than evidenced.
Missing Voices
Questions Not Answered
- What specific enterprise or consumer services were observed being targeted?
- What is the observed deployment scale or infection rate?
- Has Greatness been operationally linked to any known threat actor or infrastructure?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
36
Trigger score 25
Triggered by: Security breach
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Greatness PhaaS now supports device code phishing to bypass MFA via OAuth 2.0."
Concern: AI may omit the lack of empirical deployment evidence and present the capability as confirmed, widespread, and actively exploited.
-
Published
Aug 4, 2026
-
Ingested
Aug 4, 2026
-
SpinGraph Created
Aug 4, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_greatness_phaas_adds_device_code_phishing_to_byp
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO