Microsoft disrupts ONNX phishing-as-a-service infrastructure
ID: f6282e04-c9c1-553b-a11c-9e039ed824e9
STIX ID: report--f6282e04-c9c1-553b-a11c-9e039ed824e9
Feed Name: Bleeping Computer
Threat Score
Microsoft seized 240 domains used by ONNX (aka Caffeine/FUHRER), a large phishing-as-a-service that sold subscription phishing kits with built-in 2FA bypass and QR-code "quishing" capabilities, which were responsible for tens to hundreds of millions of phishing emails targeting Microsoft 365 users and financial sector employees; the operation stopped after the operator's identity was disclosed and a court order redirected the infrastructure to Microsoft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
