logo

ONNX Store: Phishing-as-a-Service Platform Targeting Financial Institution

ID: d751d7ea-f531-5fdd-ac8c-b064f14870a8

STIX ID: report--d751d7ea-f531-5fdd-ac8c-b064f14870a8

Feed Name: EclecticIQ

Threat Score
75/100

Date Published: 2024-06-18

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

Executive Summary — EclecticIQ analysts discovered active phishing campaigns leveraging an ONNX Store Phishing-as-a-Service platform that distributes QR-coded malicious PDFs to redirect victims to Microsoft 365–style AiTM phishing pages, capturing credentials and 2FA tokens in real time; the report details technical analysis, infrastructure overlaps with the Caffeine kit, attribution to an Arabic-speaking actor (MRxC0DER), IOCs, YARA detection rules, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.