logo

ONNX phishing service targets Microsoft 365 accounts at financial firms

ID: 886f0798-195b-5a39-8aba-ebb280bbb073

STIX ID: report--886f0798-195b-5a39-8aba-ebb280bbb073

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new phishing-as-a-service called ONNX Store (likely a rebrand of the Caffeine kit) is actively targeting Microsoft 365/Office 365 users at financial firms by sending malicious PDFs with QR codes that lead to credential- and 2FA-harvesting pages; the platform supports Telegram-based management, 2FA bypass via live credential relay, encrypted obfuscated JavaScript, Cloudflare protection, bulletproof hosting, and tiered subscriptions, and researchers recommend blocking untrusted PDF/HTML attachments, restricting access to suspicious HTTPS sites, and deploying FIDO2 hardware keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.