Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Overview
The phishing-as-a-service toolkit known as Greatness has added a new feature that allows attackers to use device code phishing to bypass Multi-Factor Authentication (MFA). This technique exploits the OAuth 2.0 Device Authorization Grant, a legitimate protocol, to gain unauthorized access to user accounts. By doing so, attackers can steal authentication tokens and control user accounts without needing to compromise passwords directly. This development is concerning as it poses risks to a wide range of applications and services that rely on MFA for security, making it easier for cybercriminals to execute their plans. Organizations and users must be vigilant and update their security practices to mitigate the risks associated with this evolving threat.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: OAuth 2.0 Device Authorization Grant, MFA implementations
- Action Required: Users should review and strengthen their MFA settings, utilize additional security measures such as hardware tokens, and stay informed about phishing tactics to enhance their defenses.
- Timeline: Newly disclosed
Original Article Summary
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and
Impact
OAuth 2.0 Device Authorization Grant, MFA implementations
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should review and strengthen their MFA settings, utilize additional security measures such as hardware tokens, and stay informed about phishing tactics to enhance their defenses.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Phishing, Update.