```

A major phishing-as-a-service (PhaaS) platform known as "Greatness" has significantly expanded its attack toolkit, moving beyond simple credential theft to deploy sophisticated adversary-in-the-middle (AiTM) and device-code phishing campaigns designed to compromise Microsoft 365 accounts, according to a report from BleepingComputer.

The platform’s evolution represents a major advancement in cloud identity threats. By using AiTM proxy infrastructure, attackers can now intercept authentication sessions immediately after a user completes a multi-factor authentication (MFA) challenge, capturing the session cookie and rendering the traditional MFA barrier ineffective. This method allows for session hijacking without needing to crack the user's password or second factor.

Complementing this, Greatness has integrated device-code phishing into its workflow. In this attack, users are manipulated into voluntarily entering a one-time authorization code—often received via a convincing phishing lure—on a legitimate Microsoft sign-in page. This grants the attacker direct access to the account without triggering typical security alerts.

A key element of these campaigns is the exploitation of trust in common business tools. The PhaaS service provides operators with templates to spoof notifications from platforms like RingCentral, framing malicious authentication requests as routine alerts for missed calls, voicemails, or service updates to increase the chance of user compliance.

The subscription-based model of Greatness has effectively industrialized these advanced techniques. Features once requiring significant technical skill—such as real-time proxy dashboards, automated routing, and dynamic phishing page generation—are now available as pay-as-you-go services, dramatically lowering the barrier for launching large-scale identity attacks.

In response to these developments, security experts are urging organizations to pivot toward phishing-resistant authentication methods. The primary recommendation is a mandatory transition to FIDO2 security keys or platform-native passkeys, which cryptographically bind the authentication to the legitimate domain and are inherently immune to proxy-based interception.

For remaining sessions, administrators must harden Microsoft 365 Conditional Access policies. This includes reducing session token lifetimes, enforcing Continuous Access Evaluation (CAE), and blocking all legacy authentication protocols. Enhanced monitoring for anomalous OAuth device-code authorization requests and irregular session token activity is also critical.

Security awareness programs must also adapt, specifically educating users on the threat of cloud-service pretext lures and the danger of entering unsolicited device codes. The core lesson: never enter authentication codes prompted by an unexpected email or message.

The capabilities demonstrated by the Greatness platform underscore a broader industry reality: identity is now the primary attack surface. As these PhaaS ecosystems mature, maintaining security for cloud environments will require a steadfast commitment to cryptographic authentication, zero-trust access principles, and continuous verification.



根據BleepingComputer的報告,一個名為「Greatness」的大型釣魚即服務(PhaaS)平台已大幅擴展其攻擊工具包,從簡單的憑證竊取轉向部署複雜的中間人(AiTM)攻擊和裝置代碼釣魚活動,專門針對Microsoft 365賬戶。

該平台的演進代表雲端身份威脅的重大突破。透過使用AiTM代理基礎設施,攻擊者現在可以在用戶完成多因素驗證(MFA)挑戰後立即截取認證會話,捕獲會話Cookie,使傳統的MFA屏障失效。這種方法無需破解用戶密碼或第二因素即可實現會話劫持。

作為補充,Greatness已將裝置代碼釣魚整合到其攻擊流程中。在這種攻擊中,用戶被誘導自願輸入一次性授權代碼——通常透過逼真的釣魚誘餌獲取——在合法的Microsoft登入頁面上。這讓攻擊者無需觸發典型安全警報即可直接訪問賬戶。

這些活動的關鍵要素是利用對常見商業工具的信任。該PhaaS服務為運營者提供模板,偽裝來自RingCentral等平台的通知,將惡意認證請求包裝成錯過的來電、語音郵件或服務更新等常規警報,以提高用戶遵從的機會。

Greatness的訂閱模式有效地將這些先進技術工業化。曾需大量技術能力的功能——如實時代理儀表板、自動路由和動態釣魚頁面生成——現在作為按需付費服務提供,大幅降低了發動大規模身份攻擊的門檻。

針對這些發展,安全專家敦促組織轉向抗釣魚的認證方法。主要建議是強制過渡到FIDO2安全密鑰或平台原生通行密鑰,這些方法透過加密將認證綁定到合法網域,從本質上免疫基於代理的截取。

對於剩餘的會話,管理員必須強化Microsoft 365條件訪問策略。這包括縮短會話令牌有效期、強制執行持續訪問評估(CAE)以及阻止所有傳統認證協議。同時,加強監控異常的OAuth裝置代碼授權請求和異常會話令牌活動也至關重要。

安全意識計劃也必須適應,特別教育用戶雲端服務託詞誘餵的威脅以及輸入未經請求的裝置代碼的危險。核心教訓是:切勿輸入意外電子郵件或訊息提示的認證代碼。

Greatness平台展現的能力凸顯了一個更廣泛的行業現實:身份現已成為主要的攻擊面。隨著這些PhaaS生態系統的成熟,維護雲端環境的安全將需要堅定承諾加密認證、零信任訪問原則和持續驗證。

新聞來源 / Original News Source