Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Key points
- Greatness, a rent-a-phishing-kit sold to criminals, has added support for device code phishing, a technique that hijacks a legitimate Microsoft sign-in flow.
- The trick lets attackers bypass multi-factor authentication (MFA), the second check like a code from your phone, and walk away with a working session token.
- Device code phishing has been used in the wild by suspected Russian state groups tracked as Storm-2372 by Microsoft.
- The kit already supported adversary-in-the-middle phishing, where the fake login page silently relays what you type to the real site.
- Ordinary users should treat any request to type a short code into microsoft.com/devicelogin as suspicious unless they started it themselves.
A popular criminal toolkit called Greatness has picked up a nasty new capability. It can now run what analysts call device code phishing, and it is aimed squarely at getting past the extra login checks most companies rely on.
Greatness is sold as phishing-as-a-service, meaning criminals rent it by the month the way a small business rents accounting software. The Hacker News first flagged the update. The kit is tracked by several vendors as one of the more polished commodity phishing platforms targeting Microsoft 365 accounts.
What is device code phishing, in plain English?
It is a scam that abuses a real Microsoft login feature designed for devices without keyboards, like smart TVs or printers. The attacker starts a real sign-in on their own machine, gets a short code from Microsoft, then tricks you into typing that code into the genuine Microsoft page. You approve it. They get in.
Because the login happens on Microsoft's own servers, your MFA prompt looks completely normal. You approve the push notification. What you are actually approving is the attacker's session, not your own.
The end prize is a session token, a small file your browser holds after you log in that proves you are you. Steal the token and the attacker does not need your password or your MFA code again for the life of that token.
Who is already using this trick?
Nation-state crews got there first. Microsoft has tied a run of device code phishing attacks through 2024 and 2025 to a group it tracks as Storm-2372, which it assesses with medium confidence aligns with Russian state interests. Targets included government, defence, telecoms and NGOs.
Other researchers have flagged overlapping tradecraft with clusters linked to Russian intelligence services, though attribution across these groups is messy and I would not put weight on any single-source call.
What is new is the technique showing up in a rented crimeware kit. That lowers the bar. You no longer need a state budget to run this attack. You need a subscription.
How is Greatness different from a normal phishing page?
Greatness already offered adversary-in-the-middle phishing, sometimes shortened to AiTM. In that setup the fake login page acts as a silent middleman, passing your username, password and MFA code to the real Microsoft site in real time and stealing the resulting session cookie.
Adding device code phishing gives customers of the kit a second route. If the AiTM path gets blocked by conditional access rules, the device code path may still work, because it uses a genuine Microsoft URL that most security tools trust.
| Technique | What the victim sees | What defeats it |
|---|---|---|
| Classic phishing | Fake login page | MFA, password managers |
| Adversary-in-the-middle | Fake login page proxying the real one | Phishing-resistant MFA, FIDO2 keys |
| Device code phishing | Real Microsoft page asking for a short code | User caution, conditional access, disabling device code flow |
What should ordinary users do?
Be suspicious of any message, email, Teams chat or SMS, that asks you to visit microsoft.com/devicelogin and type in a code someone sent you. If you did not start the sign-in yourself, do not enter the code. That short string is the key to your account.
If you did enter one by mistake, tell your IT team fast. They can revoke the session before the attacker uses it.



