ONNX Store: Phishing-as-a-Service Platform Targeting Financial Institution
ID: d751d7ea-f531-5fdd-ac8c-b064f14870a8
STIX ID: report--d751d7ea-f531-5fdd-ac8c-b064f14870a8
Feed Name: EclecticIQ
Threat Score
Executive Summary — EclecticIQ analysts discovered active phishing campaigns leveraging an ONNX Store Phishing-as-a-Service platform that distributes QR-coded malicious PDFs to redirect victims to Microsoft 365–style AiTM phishing pages, capturing credentials and 2FA tokens in real time; the report details technical analysis, infrastructure overlaps with the Caffeine kit, attribution to an Arabic-speaking actor (MRxC0DER), IOCs, YARA detection rules, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
