ONNX Store was a phishing-as-a-service operation that targeted financial-sector employees with emails containing PDF attachments and QR codes. Scanning a code could take a victim to a fake Microsoft 365 sign-in page that relayed credentials and phishable multifactor authentication (MFA) information to attackers in real time. The activity was reported in 2024; on November 22, 2024, Microsoft said it had seized 240 fraudulent websites associated with the ONNX-branded supplier. That disruption does not make QR-code phishing or session theft obsolete.
What ONNX Store was
ONNX Store was a criminal phishing-as-a-service (PhaaS) operation, not a legitimate software product. PhaaS packages capabilities such as login-page templates, hosting, campaign management and credential collection so customers can run phishing campaigns without building all the infrastructure themselves. EclecticIQ observed campaigns beginning in February 2024 and published its findings on June 18, 2024; FINRA also warned firms about the operation. EclecticIQ’s account and FINRA’s alert describe attacks aimed at Microsoft 365 users in financial organizations across EMEA and the Americas.
Reporting described Telegram-based customer management and support, customizable Microsoft 365 and Office 365 pages, delivery services, redirects and tools intended to capture MFA information or authentication cookies. This kind of packaged service lowers the technical barrier to account theft: the customer can buy access to capabilities that would otherwise require expertise in web development, hosting and campaign operations. BleepingComputer’s June 2024 report, summarizing EclecticIQ’s findings, also published historical subscription tiers and prices. Those prices describe criminal-service offerings reported at the time, not current availability or legitimate software pricing.
EclecticIQ assessed ONNX as a rebranded evolution of the Caffeine phishing platform. Microsoft later said that Abanoub Nady, also known as MRxC0DER, was behind the ONNX-branded supplier operation. These are attributed assessments and statements, not a basis for assigning every campaign using similar techniques to one operator.
#1 Best Overall
How the QR-code attack worked
The reported campaign combined a familiar workplace lure with a less familiar route to a fake login page. FINRA and EclecticIQ described emails purporting to come from HR or another trusted function, often referencing a salary or compensation update. A PDF attachment styled to resemble Adobe or Microsoft material contained a QR code. The victim scanned it—potentially using a personal phone—and was directed to a Microsoft 365 lookalike page.
- An employee received a plausible HR or compensation-themed email with a PDF attachment.
- The employee opened the PDF and scanned its QR code, often with a mobile device.
- The code opened a fraudulent page imitating Microsoft 365 sign-in.
- The victim entered account credentials and, if prompted, a one-time code or other phishable MFA information.
- The phishing service relayed authentication data to the legitimate service, allowing the attacker to try to capture an authenticated session before the relevant authentication opportunity expired.
This is called quishing: phishing delivered through a QR code. The code is a link in a different form, not a trust signal. A PDF need not exploit a software flaw to be dangerous; its QR code can simply move the victim to a malicious site.
QR codes themselves are not malicious. Legitimate sign-in and passkey processes can use them too. The warning sign is an unexpected message that asks you to scan a code and authenticate, especially for payroll, payments or account recovery—not the QR format alone.
Why a QR code can complicate email defenses
A mail gateway may inspect a PDF without following or fully evaluating the destination encoded in its image. Scanning the code on a personal phone also shifts the interaction away from the managed computer that received the email. The organization may have less visibility into the mobile browser, and the employee may perceive scanning as safer than clicking a link.
Free tools Windows power users keep installed
One-click scans. No signup required.
FINRA specifically warned that personal mobile devices used under bring-your-own-device arrangements can make this activity harder for conventional endpoint controls to monitor. That is a visibility gap, not proof that every QR code or phone-based sign-in is unsafe. Treat unsolicited QR codes as links: assess the context, use trusted sign-in routes, and report suspicious messages.
Why ordinary MFA could be intercepted
ONNX was reported to use an adversary-in-the-middle (AiTM) approach: the victim interacts with a fraudulent site while the attacker’s service relays information to the real identity provider. If the victim supplies a password and a phishable MFA code or approves a prompt, the attacker may use the relayed authentication to obtain a session. In that case, turning on MFA alone does not necessarily stop the attack.
This does not mean ONNX defeated every form of MFA. One-time codes sent by SMS, email or an authenticator, and push approvals, can be exposed to relay or social engineering. A stolen session token may also let an attacker access an account without repeating the full sign-in flow. Phishing-resistant methods are designed to bind authentication to the legitimate site, making a fake sign-in page much less useful. Microsoft identifies FIDO2 security keys and passkeys, Windows Hello for Business, and certificate-based authentication as phishing-resistant options in its phishing-resistant MFA guidance.
These methods materially reduce phishing risk, but they do not make account takeover impossible. Endpoint compromise, recovery-process abuse, token theft and policy misconfiguration remain separate concerns.
Why financial firms were attractive targets
The observed target set included banks, credit-union service providers, private-funding firms and other financial organizations—not just U.S. banks. FINRA’s warning addressed firms in its member population, while EclecticIQ described activity in EMEA and the Americas. Microsoft noted that financial services were heavily targeted because of the sensitivity of the data and transactions the sector handles.
A compromised Microsoft 365 mailbox can expose client information, deal documents, payroll data, payment instructions and internal communications. Attackers may use access to impersonate an employee, redirect vendor payments, send more phishing from a trusted account or seek a foothold for further intrusion, including ransomware activity.
What happened to the ONNX-branded operation
On November 22, 2024, Microsoft said it had seized 240 fraudulent websites associated with Egypt-based supplier Abanoub Nady, also known as MRxC0DER, who used the ONNX brand to sell do-it-yourself phishing kits. Microsoft’s announcement describes that disruption. It is not evidence that the exact 2024 storefront continues operating unchanged today, nor does a seizure establish that every related technique or criminal customer disappeared. The incident is best understood as a documented example of commercialized phishing and a reminder that other operators can reuse the same methods.
What Microsoft 365 administrators should prioritize
1. Require phishing-resistant sign-in for high-risk accounts
Prioritize administrators, finance and payroll staff, executives, and employees who approve payments or handle sensitive transactions. Use FIDO2 security keys, passkeys, Windows Hello for Business or certificate-based authentication where the organization’s identity setup supports them. Microsoft’s passkey and FIDO2 deployment guidance explains the Entra setup considerations. Plan enrollment, replacement keys, accessibility, travel and account recovery before making a stronger method mandatory.
Best Value
2. Apply access policy to the risk
Use Microsoft Entra Conditional Access to require stronger authentication for sensitive applications and higher-risk sign-ins. Where appropriate, make access depend on device compliance or other device-based conditions. Microsoft’s token guidance recommends layered mitigations that include phishing-resistant credentials, risk- and device-based access policies, and device-bound tokens where available. These controls should be designed around the organization’s architecture rather than treated as interchangeable switches.
3. Inspect suspicious messages and PDFs
Use email controls to inspect or quarantine suspicious PDF attachments, links and impersonation attempts. A blanket PDF block can disrupt payroll, lending, legal and client workflows, so consider sender reputation, sandboxing and targeted quarantine where a full block is impractical. Include QR-code attachments in realistic security exercises; training supports technical controls but cannot replace them.
4. Monitor identity and mailbox activity
Alert on unfamiliar sign-in locations or devices, anomalous access, unexpected authentication changes, suspicious OAuth consent, new mailbox rules or forwarding, and unusual sending activity. Maintain a response procedure that can disable or contain an account, revoke active sessions and refresh tokens where supported, and investigate mailbox access. Shorter token lifetimes may reduce some replay opportunities, but can add friction and are not a substitute for phishing-resistant authentication.
5. Address mobile access without assuming complete visibility
Mobile-device management and browser protections can improve oversight when employees access organizational resources from phones. Microsoft Intune can support managed mobile access, but it cannot guarantee visibility into every action on a personally owned device. Set clear access expectations for BYOD and provide a trusted way to reach work services.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What employees should do
- Do not use an unexpected email’s QR code to sign in, even when the message appears to concern salary, payroll or a work document.
- Open Microsoft 365 through a known bookmark, the organization’s normal application portal or a trusted address entered directly.
- Verify salary, payment, account-recovery and urgent document requests through a separate, known channel.
- Never enter a password or MFA code on a page reached from an unsolicited QR code.
- Report the email using your organization’s reporting process. If you entered credentials or approved a prompt, contact IT or security immediately rather than waiting for an alert.
Do not rely only on a page’s visual appearance or a quick glance at its address. Redirects, lookalike names and other tricks can make fraudulent destinations difficult to spot.
Quick Recap
If someone interacted with a suspected phishing page
- Contain the account. Follow the incident plan to disable or otherwise limit access while the security team assesses the event.
- Reset credentials from a clean device. If the password was entered, treat it as exposed even if the user did not complete MFA.
- Revoke sessions and tokens where possible. A password change alone may not end an already authenticated session.
- Check authentication methods and account persistence. Review recent sign-ins, authentication details, registered devices, OAuth consent, mailbox rules, forwarding settings and sent mail; remove unauthorized changes and re-verify MFA methods if compromise is suspected.
- Find related messages and affected recipients. Search for the same lure and determine whether a compromised mailbox sent additional messages.
- Preserve evidence and coordinate notifications. Keep the original email, PDF, QR image, headers, destination information, timestamps and relevant logs. Involve payment-control teams and affected vendors where warranted.
- Report through appropriate channels. FINRA points firms to the FBI, IC3 and CISA reporting channels in its cybersecurity alert.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




