A major phishing-as-a-service (PhaaS) toolkit has automated a potent method for bypassing multi-factor authentication, a move security experts warn dramatically increases the scale of a threat previously reserved for more skilled attackers. The criminal platform, known as "Greatness," now includes support for device code phishing, which exploits a legitimate feature of the OAuth 2.0 protocol to hijack user sessions and steal login tokens.

According to reporting by The Hacker News, the addition transforms a sophisticated social engineering technique into a turnkey capability for the platform's customers. Previously, executing such an attack required manual setup and technical know-how. Greatness already offered adversary-in-the-middle credential harvesting and consent abuse capabilities; the integration of device code phishing further lowers the barrier to entry, allowing lower-skilled operators to launch large-scale identity theft campaigns.

The core vulnerability lies in the protocol's design, not a software flaw. The attack works by tricking users into approving a legitimate authentication request they did not initiate, or entering a one-time code on an attacker-controlled page. This renders conventional MFA defenses, such as push notifications or TOTP codes, ineffective, as users are manipulated into completing a valid login ceremony for the attacker.

Security analysts stress that this commoditization demands an immediate, layered response from enterprises. A primary recommendation is to accelerate the migration of critical systems and privileged accounts to phishing-resistant authentication standards like FIDO2 and WebAuthn, which are immune to such relay attacks. Concurrently, organizations must audit their identity infrastructure to map where the OAuth device code flow is enabled, applying strict conditional access policies or disabling it where not operationally essential.

Enhanced detection and user awareness are also critical. Security teams should monitor authentication logs for anomalies, such as unexpected spikes in device code grant requests. Training programs must be updated to explicitly instruct users to never approve uninitiated login prompts or enter codes from untrusted sources. As phishing platforms continue to evolve, the strategic focus must shift from reliance on single-factor defenses to comprehensive identity governance and continuous risk assessment.


一個主要的網絡釣魚即服務(PhaaS)工具包已將一種強效的繞過多重認證方法自動化,安全專家警告,此舉將大幅擴大以往僅限於高技能攻擊者的威脅規模。這個名為「Greatness」的犯罪平台現已支援裝置代碼網絡釣魚,該功能利用 OAuth 2.0 協議的合法特性來劫持用戶會話並竊取登入權杖。

據 The Hacker News 報導,此項新增功能將複雜的社會工程技術轉化為平台客戶的現成能力。以往,實施此類攻擊需要手動設置與專業技術知識。Greatness 平台原本已提供中間人憑證收割與授權濫用功能;此次整合裝置代碼網絡釣魚進一步降低了入門門檻,令技術較遜色的操作者亦能發動大規模的身分盜竊活動。

核心漏洞在於協議設計本身,而非軟件缺陷。該攻擊手法透過誘騙用戶批准其並未主動發起的合法認證請求,或在攻擊者控制的頁面輸入一次性代碼來運作。這使得傳統的 MFA 防禦措施(例如推送通知或 TOTP 代碼)失效,因為用戶在不知情下被操縱,為攻擊者完成了有效的登入程序。

安全分析師強調,此類攻擊工具的商品化要求企業立即採取多層次的應對措施。首要建議是加快將關鍵系統與特權帳戶遷移至抗網絡釣魚的認證標準(如 FIDO2 和 WebAuthn),這些標準可免疫於此類中繼攻擊。同時,機構必須審計其身分基礎設施,全面檢視 OAuth 裝置代碼流程的啟用情況,並實施嚴格的條件式存取策略,或在非營運必需的情況下將其停用。

加強偵測能力與提升用戶意識同樣至關重要。安全團隊應密切監控認證日誌中的異常情況,例如裝置代碼授權請求出現意外激增。培訓計劃必須更新,明確指示用戶切勿批准非主動發起的登入提示,或輸入來自不受信任來源的代碼。隨著網絡釣魚平台持續演進,企業的戰略重心必須從依賴單一因素防禦,轉向全面的身分治理與持續風險評估。

新聞來源 / Original News Source