HomeSecurityNew phishing service ONNX targets Microsoft 365 accounts

New phishing service ONNX targets Microsoft 365 accounts

A new phishing-as-a-service (PhaaS), called ONNX Store, is targeting accounts Microsoft 365 of financial services employees. What’s unique about these phishing attacks is the use of QR codes in PDF attachments.

ONNX phishing Microsoft 365

The platform can target Microsoft 365 and Office 365 and operates through Telegram bots. It has mechanisms to bypass two-factor authentication ( 2FA), which makes it quite effective.

The ONNX phishing platform was discovered by researchers at EclecticIQ, who believe it is a revamped version of the Caffeine. Mandiant discovered the Caffeine service in October 2022, when the platform targeted Russian and Chinese platforms instead of Western services.

Attacks with the new phishing platform ONNX

EclecticIQ observed the ONNX attacks in February 2024. The phishing emails contained PDF attachments with malicious QR codes that targeted employees at banks, credit card providers, and private finance companies.

See also: New phishing toolkit uses PWA to steal login credentials

The emails impersonate the human resources (HR) departments of the target companies and use alleged salary updates as the subject line of the email to convince employees to open the PDFs.

Scanning the QR code on a mobile device bypasses phishing protections at targeted organizations, leading victims to phishing pages that mimic the legitimate Microsoft 365 login interface.

At that point, the victim is prompted to enter credentials and 2FA token on the fake login page. The data is recorded on the phishing site and transmitted to the attackers in real time. This allows them to compromise the target's account before the authentication expires.

Attackers can then access the compromised email account and steal sensitive information, such as emails and documents. They can even sell the login credentials to other cybercriminals.

ONNX: A new serious threat in the field of phishing

For cybercriminals, the ONNX phishing platform is an exciting and cost-effective platform.

The hub of operations is located on Telegram, where bots allow customers to manage phishing operations through an intuitive interface. Additionally, there are dedicated support channels to provide any assistance.

Phishing templates for targeting Microsoft Office 365 accounts are customizable and webmail services are available for sending phishing emails to targets.

See also: Phishing emails promote malicious scripts via Windows search protocol

Additionally, encrypted JavaScript code that is decrypted when the page loads, which helps avoid detection by security and scanners.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

New phishing service ONNX targets Microsoft 365 accounts

Finally, ONNX uses Cloudflare to prevent its domains from being taken down.

Phishing service ONNX offers four subscription levels: Webmail Normal ($150/month), Office Normal ($200/month), Office Redirect ($200/month), and Office 2FA Cookie Stealer ($400/month). Each offers different capabilities to attackers.

Overall, ONNX Store poses a significant threat to Microsoft 365 account holders, especially for companies operating in the financial industry.

Phishing protection

Users should be cautious and suspicious of emails they receive without expecting it. They should always be aware of the latest phishing techniques and learn how to recognize suspicious emails or scams . It is advisable to avoid clicking on links and attachments that look suspicious. Also, personal and financial information should not be given to third parties.

See also: Phishing attacks: Significant increase in the US and Europe

Using reliable security software that provides protection against malware and viruses is also helpful. This can help detect and avoid phishing attacks.

Next, users should be careful about the apps they download and install on their devices. They should only download apps from trusted sources and avoid apps that look suspicious or don't have good reviews.

Finally, it is essential to use different passwords for different accounts. Don't forget two-factor authentication where available, for an extra layer of security for your accounts.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS