SECURITY·중요도 8·2026. 08. 04.·The Hacker News
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
── KO ──────────────────
PhaaS 툴킷 Greatness가 MFA를 우회하는 장치 코드 피싱을 추가했습니다.
Greatness라는 상업적 피싱-서비스(PhaaS) 툴킷이 장치 코드 피싱을 지원하기 시작했습니다. 이는 OAuth 2.0 장치 인증 부여를 악용하여 다단계 인증(MFA)을 우회하고 사용자 계정을 탈취하는 증가하는 사이버 위협입니다. 이는 새로운 공격 벡터를 제공하여 사용자의 보안을 위험에 빠뜨릴 수 있습니다.
── EN ──────────────────
The PhaaS toolkit Greatness adds device code phishing to bypass MFA.
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has started supporting device code phishing. This method abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize user accounts. This introduces a new attack vector that can compromise user security.