๐จ ๐ข๐๐๐๐ต ๐ง๐ผ๐ธ๐ฒ๐ป ๐๐ฏ๐๐๐ฒ ๐๐ ๐๐ฟ๐ผ๐๐ถ๐ป๐ด: ๐๐ฟ๐ฒ๐ฎ๐๐ป๐ฒ๐๐ ๐ฅ๐ฒ๐๐๐ฟ๐ป๐ ๐๐ถ๐๐ต ๐๐ฒ๐๐ถ๐ฐ๐ฒ ๐๐ผ๐ฑ๐ฒ ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด
We've identified renewed activity associated with the Greatness #PhaaS, which combines #AiTM and Device Code #Phishing to target Microsoft 365 Accounts.
โ ๏ธ Device Code Phishing abuses Microsoft's legitimate device authorization flow to obtain access tokens without directly collecting passwords or MFA codes. This shifts risk from credential theft to token abuse, reducing traditional phishing indicators for SOC teams to detect and investigate.
โ๏ธ Greatness promotes token- and cookie-based access to Microsoft 365 accounts through its Telegram channel, advertising passwordless and code-less account compromise scenarios.
Observed capabilities include:
๐น Device Code Phishing for M365 token theft
๐น Phishing templates impersonating DocuSign, OneDrive, Outlook, and Voicemail
๐น Country-targeted login lures
๐น Cloudflare-hosted phishing links
๐น Keyword-based targeting engine
๐น Centralized administration panel
๐จโ๐ป Review the analysis session, investigate the phishing flow, and validate detection coverage: https://app.any.run/tasks/dd97835c-8a07-4917-ba23-cb8d8493b174/?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_phaas&utm_term=100626&utm_content=linktoservice
๐ Track Device Code Phishing activity associated with Greatness and uncover related infrastructure in #ANYRUN TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_phaas&utm_content=linktotilookup&utm_term=100626#%7B%22query%22:%22threatName:%5C%22greatness%5C%22%20and%20threatName:%5C%22oauth-ms-phish%5C%22%22,%22dateRange%22:180%7D
๐ Strengthen phishing detection and accelerate response across your SOC with #ANYRUN: https://any.run/phishing/?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_phaas&utm_term=100626&utm_content=linktophishinglanding
#cybersecurity #infosec