logo

Microsoft seizes websites tied to Egypt-based DIY phishing kit-maker

ID: fb28c743-7371-50de-9873-b5903c312a16

STIX ID: report--fb28c743-7371-50de-9873-b5903c312a16

Feed Name: CyberScoop

Threat Score
72/100

Date Published: 2024-11-21

Date Updated: 2026-04-21

Author: Tim Starks

...
...

Microsoft seized 240 websites linked to an Egypt-based operator known as MRxC0DER who sold ONNX phishing kits that perform adversary-in-the-middle (AiTM) attacks to bypass multifactor authentication; the kits have been used to target Microsoft 365 users and financial services, and researchers warn the service represents a sophisticated phishing-as-a-service threat even though domain seizures can only temporarily disrupt the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.