Dossier
phishing-as-a-service (PhaaS)
Coverage of phishing-as-a-service (PhaaS) in the Nexus archive.
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, which exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal user tokens. This method allows attackers to seize control of accounts by leveraging a legitimate authentication protocol.
- FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI has issued a warning about the Kali365 phishing-as-a-service platform, which exploits OAuth device code authentication to hijack Microsoft 365 accounts. The service steals session tokens and bypasses multi-factor authentication (MFA), posing a significant cybersecurity threat.