'ONNX' MFA Bypass Targets Microsoft 365 Accounts
ID: a8f7339d-405a-5645-8820-125a3aabd664
STIX ID: report--a8f7339d-405a-5645-8820-125a3aabd664
Feed Name: Dark Reading
Date Published: 2024-06-19
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
EclecticIQ researchers attribute a widespread phishing-as-a-service campaign (ONNX Store) targeting financial firms’ Microsoft 365 accounts; attackers send PDF attachments containing QR codes that lead to typosquatted phishing pages which use encrypted JavaScript and WebSocket-based AitM techniques to steal credentials and bypass 2FA in real time. The report details the campaign infrastructure (Telegram-based PhaaS, similarities to Caffeine), technical evasion methods, and defensive recommendations including blocking untrusted PDF/HTML attachments, employee QR-code awareness, DNSSEC, FIDO2 hardware keys, short token lifetimes, and monitoring for anomalous logins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
