logo

'ONNX' MFA Bypass Targets Microsoft 365 Accounts

ID: a8f7339d-405a-5645-8820-125a3aabd664

STIX ID: report--a8f7339d-405a-5645-8820-125a3aabd664

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-06-19

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

EclecticIQ researchers attribute a widespread phishing-as-a-service campaign (ONNX Store) targeting financial firms’ Microsoft 365 accounts; attackers send PDF attachments containing QR codes that lead to typosquatted phishing pages which use encrypted JavaScript and WebSocket-based AitM techniques to steal credentials and bypass 2FA in real time. The report details the campaign infrastructure (Telegram-based PhaaS, similarities to Caffeine), technical evasion methods, and defensive recommendations including blocking untrusted PDF/HTML attachments, employee QR-code awareness, DNSSEC, FIDO2 hardware keys, short token lifetimes, and monitoring for anomalous logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.