Microsoft disrupts ONNX phishing-as-a-service infrastructure

Teilen:

Microsoft has seized 240 domains used by customers of ONNX, a phishing-as-a-service (PhaaS) platform, to target companies and individuals across the United States and worldwide since at least 2017.

According to Microsoft’s Digital Defense Report 2024, ONNX (also known as Caffeine and FUHRER) was the top Adversary in the Middle (AitM) phishing service by volume of phishing messages during the first half of 2024. Tens to hundreds of millions of phishing emails targeted Microsoft 365 accounts each month and customers of various other tech companies.

“These ‘do it yourself’ kits make up a significant portion of the tens to hundreds of millions of phishing messages observed by Microsoft each month and the fraudulent ONNX operation was a top 5 supplier in the first half of 2024,” Microsoft told BleepingComputer.

“The fraudulent ONNX operation offered phishing kits designed to target a variety of companies across the technology sector, including Google, DropBox, Rackspace, and Microsoft.”

ONNX promoted and sold the phish kits on Telegram using several subscription models (Basic, Professional, and Enterprise), ranging from $150 to $550 monthly.

The attacks, also controlled via Telegram bots, came with built-in two-factor authentication (2FA) bypass mechanisms and most recently targeted financial firms’ employees (at banks, credit union service providers, and private funding firms) using QR code phishing (also known as quashing) tactics.

These emails included PDF attachments containing malicious QR codes that redirected potential victims to pages resembling legitimate Microsoft 365 login pages and asked them to enter their credentials.

“Threat actors leverage quishing attacks because victims will typically scan QR codes on their personal mobile devices (which the victim may use for business purposes, as part of their firms’ Bring Your Own Device (BYOD) program),” U.S. securities industry regulator FINRA also warned in a recent alert. “As a result, these attacks are exceptionally difficult to monitor with typical endpoint detection.”

ONNX QR code phishing email sample
ONNX QR code phishing email sample (EclecticIQ)
​Cybercriminals using ONNX have been particularly effective in carrying out their attacks as the phishing kits help bypass two-factor authentication (2FA) by intercepting 2FA requests. They also use bulletproof hosting services that delay phishing domains’ takedowns and encrypted JavaScript code that decrypts itself during page load, adding an extra layer of obfuscation to evade detection by anti-phishing scanners.

“These attacks present a unique challenge for cybersecurity providers as they appear as an unreadable image to security and scanning features,” said Steven Masada, Assistant General Counsel at Microsoft’s Digital Crimes Unit, today.

ONNX operations abruptly stopped in June after Dark Atlas security researchers discovered and disclosed its owner’s identity, Abanoub Nady (also known online as MRxC0DER).

“Through a civil court order unsealed today in the Eastern District of Virginia, this action redirects the malicious technical infrastructure to Microsoft, severing access of threat actors, including the fraudulent ONNX operation and its cybercrime customers, and permanently stopping the use of these domains in phishing attacks in the future,” Masada added.

“Our goal in all cases is to protect customers by severing malicious actors from the infrastructure required to operate and to deter future cybercriminal behavior by significantly raising the barriers of entry and the cost of doing business. We are joined by co-plaintiff LF (Linux Foundation) Projects, LLC, the trademark owner of the actual registered ‘ONNX’ name and logo.”

You can find the complete list of 240 domains seized in the action in the unsealed complaint appendixes.

In October, Microsoft and the Justice Department also disrupted Russian ColdRiver FSB hackers’ attack infrastructure by seizing over 100 domains used in spear-phishing attacks against U.S. government employees and Russian nonprofit organizations.

Last December, the company’s Digital Crimes Unit also took action against a major cybercrime-as-a-service provider (Storm-1152) that registered over 750 million fraudulent Microsoft email accounts and raked in millions by selling them to other cybercriminals.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:07 am, Juli 2, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 78 %
Druck: 1015 mb
Wind: 6 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 50%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0.26 mm 26% 11 mph 80 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 12 mph 54 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 13 mph 95 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 17°°C 1 mm 100% 12 mph 91 % 1009 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 5 mph 79 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 80 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 73 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.2 mm 20% 7 mph 71 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0.26 mm 26% 8 mph 45 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 11 mph 32 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 35 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 39 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,281.38
-1.86%
Ethereum(ETH)
€2,032.91
-3.74%
Fesseln(USDT)
€0.85
-0.02%
XRP(XRP)
€1.84
-3.27%
Solana(SOL)
€124.29
-5.16%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.133739
-4.58%
Shiba Inu(SHIB)
€0.000009
-2.22%
Pepe(PEPE)
€0.000008
-4.97%
Nach oben scrollen