Device-Code Phishing: Bypassing MFA to Steal Tokens

A worker opens an email during a crowded afternoon. The message looks ordinary enough, perhaps a shared document or an urgent request from an internal team. Instead of asking for a password, it offers a short code and a link. The worker visits the real Microsoft sign in page, enters the code, and completes the familiar MFA prompt.

That quiet normality gives the attack its power.

The phishing as a service platform called Greatness now supports device code phishing, a method that abuses a legitimate feature in OAuth 2.0. That feature helps devices with limited keyboards, such as televisions or small hardware terminals, connect to an account. A user enters a short code on another device, confirms the login, and grants access.

Criminals have found a darker use for the same process. They create a valid device code, send it to a target, and persuade that person to complete the sign in. Once the victim approves the request, the attacker can obtain an access token. That token may let the criminal enter business services without asking for the victim’s password again.

Does MFA still works as designed?

The user approves a real request, but the user does not understand who created it or why it appeared. MFA confirms the person at the keyboard. It does not always confirm the person who started the login.

Greatness adds this method to a broader criminal toolkit. The platform also supports adversary in the middle attacks, which can capture passwords and session tokens as a victim signs in. It can abuse OAuth consent, a process that lets an application request permission to read or manage account data. The same operator panel can target several major services, including Microsoft 365, Google Workspace, iCloud, and Yahoo.

That combination matters. Greatness no longer acts like a simple page that copies a password. It resembles a packaged attack business. Its operators can choose a target, select a technique, collect tokens, and manage the campaign through shared infrastructure. The platform lowers the skill needed to launch a sophisticated intrusion.

Researchers first described Greatness publicly in 2023, after observing attacks against Microsoft 365 users that began at least a year earlier. Its latest capability shows how quickly online crime adapts. Defenders often spend months improving a control. Criminal groups can add a new function and distribute it across a ready made service.

The real weakness sits between trust and attention

Device code phishing exposes an uncomfortable truth for every security leader. A company can require MFA and still lose control of an account if employees treat every approval prompt as routine.

The challenge for the CISO in the age of AI grows sharper because attackers can now combine automation, convincing language, and detailed knowledge of a target’s work. Greatness itself does not need artificial intelligence to create danger, but the wider criminal market can use AI to produce more believable messages, adjust campaigns quickly, and test which requests make people respond.

Security teams should begin with a simple rule: employees should never enter a device code because an email, text message, or caller told them to do so. A code should start with a known task on a known device. If the employee did not request the login, the employee should cancel it and report the event.

Companies also need stronger technical controls.

Administrators should limit which applications can request account permissions, review OAuth grants, and remove permissions that users no longer need. They should monitor unusual sign ins, unfamiliar devices, sudden token use, and access from locations that do not fit a person’s normal work pattern. Security teams should treat tokens as valuable credentials, not as harmless technical details.

Phishing training also needs a reset. Old lessons focused heavily on fake login pages and suspicious spelling. Those signs still matter, but they no longer cover the threat. Training should show workers how a genuine login page can support a fraudulent request. It should explain why an unexpected code, approval prompt, or application permission deserves suspicion.

The industry should also challenge its own language. Calling MFA a complete answer creates false confidence. MFA remains essential, yet it cannot solve a problem that involves deception, consent, and stolen sessions. Security leaders need layered controls that protect the account after login, not only at the password screen.

Greatness makes that gap visible. It turns a trusted sign in process into a stage for manipulation, then packages the performance for criminals who may know very little about security. The most effective defense combines careful product settings, close monitoring, and a culture that gives workers permission to pause. A moment of doubt can protect an entire business.

Ensuring Business Continuity in a Hyper-Connected World

“91% of cyberattacks start with a phishing email.” – CSO Online

Staying at the forefront of cybersecurity innovation is crucial for business survival and competitiveness. Keeping abreast of developments in areas like blockchain security, artificial intelligence in threat detection, and advanced encryption can provide businesses with a significant advantage in safeguarding their digital assets.

Here are some key takeaways:

  1. Disable or restrict device-code authentication. Permit it only for approved devices, users, and workflows. Alert on unusual device-code requests, unfamiliar IPs, and abnormal geolocation.
  2. Adopt phishing-resistant MFA. Use FIDO2 security keys or passkeys. Do not rely solely on SMS, push approval, or codes that attackers can relay.
  3. Harden token and session controls. Apply short token lifetimes, continuous access evaluation, device compliance checks, and rapid revocation. Revoke refresh tokens immediately after suspected compromise.
  4. Detect the campaign, not merely the email. Monitor consent grants, mailbox-rule changes, impossible travel, token replay, atypical user agents, and sign-ins from proxy infrastructure. Correlate identity, endpoint, and SaaS telemetry.
  5. Strengthen human and supplier resilience. Train users to reject unsolicited device-code prompts and verify requests through a separate channel. Assess PhaaS exposure, rehearse account-takeover response, and maintain break-glass recovery procedures.

Connection to the named works: These measures apply Securing Success in a Digitally Driven World through layered identity and access protection; Navigating Cyber Threats for Sustainable Growth through threat-informed detection and third-party governance; and Building Resilience in the Age of Digital Transformation through rehearsed recovery, rapid containment, and continuity planning.

From the Author

In the face of growing cybersecurity threats, the importance of collaboration cannot be overstated. By pooling resources and expertise, professionals and organizations can develop more comprehensive and effective defense mechanisms against this escalating problem.

On my website, I make it a point to highlight stories like this to enrich my writing process and bring meaningful narratives to a wider audience. If you found this article engaging, you might enjoy other stories in the Management section or Small Business section.
For further Cybersecurity insights, check out the Cybersecurity section.

To check the original story Click here

Expand Your Horizons

Here are some free Information Security Tools TrendMicro Tools.

Cyber-V2

Mani

A seasoned professional in IT, Cybersecurity, and Applied AI, with a distinguished career spanning over 20+ years. Mr. Masood is highly regarded for his contributions to the field, holding esteemed affiliations with notable organizations such as the New York Academy of Sciences and the IEEE – Computer and Information Theory Society. His career and contributions underscores his commitment to advancing research and development in technology.

Mani Masood

A seasoned professional in IT, Cybersecurity, and Applied AI, with a distinguished career spanning...