Microsoft Dismantles ONNX: A Sophisticated Phishing-as-a-Service Threat
Detailed breakdown of Microsoft's operation to take down the ONNX phishing platform targeting Microsoft 365 accounts.
Overview: Microsoft, collaborating with global cybersecurity teams, has successfully dismantled the ONNX phishing-as-a-service (PhaaS) platform targeting Microsoft 365 accounts.
ONNX Platform Characteristics
- Specialized in attacking financial institutions
- Utilized phishing emails with malicious QR codes
- Capable of bypassing two-factor authentication
- Offered subscription tiers from $150 to $400 per month
Microsoft's Takedown Strategy
- Disabled ONNX servers and domains
- Collaborated with law enforcement
- Notified targeted organizations
Prevention Recommendations
- Restrict suspicious attachments
- Implement FIDO2 hardware keys
- Enhance employee cybersecurity training