Dodgy New Phishing Platform Targets Microsoft 365 Accounts at Financial Firms

Stu Sjouwerman | Jul 9, 2024

Phishing Platform TargetsAnalysis of the latest phishing-as-a-service (PhaaS) platform ONNX Store highlights just how successful these platforms can be.

Security analysts at threat intelligence vendor Eclectic IQ have been tracking ONNX Store, noting it’s a rebranded evolution of the Caffeine PhaaS platform. According to analysis, ONNX has been used to target financial institutions, “including banks, private funding firms and credit union service providers across the EMEA and AMER regions.”

This platform uses a combination of socially-engineered phishing emails, QR codes contained within PDF attachments, impersonated Microsoft 365 authentication pages hosted on bulletproof hosting services, proxied MFA, and encrypted JavaScript code to avoid detection.

Eclectic IQ mapped out all the services, websites, bots and more used as by this sophisticated platform:

ONNX PaaS- image001

Source: Electric IQ

It's a rather elaborate setup that should have organizations worried. Something this advanced, which takes into account just about every way a user or security solution could detect it’s a phishing attack, is troublesome.

However, the one element of the attack that even ONNX can’t mimic perfectly is the phish itself.  It requires the recipient to believe they need to open a PDF attachment and then use their mobile phone to scan the QR code to read the document.

Users that undergo continual security awareness training will realize when first receiving such an email that it’s unexpected and – therefore – suspect to begin with. 

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.