Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

ONNX Phishing Service Targeted Microsoft 365 Accounts at Financial Firms

ONNX’s 2024 phishing campaigns used PDF QR codes and real-time authentication relay to target financial-sector Microsoft 365 accounts. Here’s what the operation did, what its disruption means and how to reduce the risk.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ONNX Store was a phishing-as-a-service operation that targeted financial-sector employees with emails containing PDF attachments and QR codes. Scanning a code could take a victim to a fake Microsoft 365 sign-in page that relayed credentials and phishable multifactor authentication (MFA) information to attackers in real time. The activity was reported in 2024; on November 22, 2024, Microsoft said it had seized 240 fraudulent websites associated with the ONNX-branded supplier. That disruption does not make QR-code phishing or session theft obsolete.

What ONNX Store was

ONNX Store was a criminal phishing-as-a-service (PhaaS) operation, not a legitimate software product. PhaaS packages capabilities such as login-page templates, hosting, campaign management and credential collection so customers can run phishing campaigns without building all the infrastructure themselves. EclecticIQ observed campaigns beginning in February 2024 and published its findings on June 18, 2024; FINRA also warned firms about the operation. EclecticIQ’s account and FINRA’s alert describe attacks aimed at Microsoft 365 users in financial organizations across EMEA and the Americas.

Reporting described Telegram-based customer management and support, customizable Microsoft 365 and Office 365 pages, delivery services, redirects and tools intended to capture MFA information or authentication cookies. This kind of packaged service lowers the technical barrier to account theft: the customer can buy access to capabilities that would otherwise require expertise in web development, hosting and campaign operations. BleepingComputer’s June 2024 report, summarizing EclecticIQ’s findings, also published historical subscription tiers and prices. Those prices describe criminal-service offerings reported at the time, not current availability or legitimate software pricing.

EclecticIQ assessed ONNX as a rebranded evolution of the Caffeine phishing platform. Microsoft later said that Abanoub Nady, also known as MRxC0DER, was behind the ONNX-branded supplier operation. These are attributed assessments and statements, not a basis for assigning every campaign using similar techniques to one operator.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the QR-code attack worked

The reported campaign combined a familiar workplace lure with a less familiar route to a fake login page. FINRA and EclecticIQ described emails purporting to come from HR or another trusted function, often referencing a salary or compensation update. A PDF attachment styled to resemble Adobe or Microsoft material contained a QR code. The victim scanned it—potentially using a personal phone—and was directed to a Microsoft 365 lookalike page.

  1. An employee received a plausible HR or compensation-themed email with a PDF attachment.
  2. The employee opened the PDF and scanned its QR code, often with a mobile device.
  3. The code opened a fraudulent page imitating Microsoft 365 sign-in.
  4. The victim entered account credentials and, if prompted, a one-time code or other phishable MFA information.
  5. The phishing service relayed authentication data to the legitimate service, allowing the attacker to try to capture an authenticated session before the relevant authentication opportunity expired.

This is called quishing: phishing delivered through a QR code. The code is a link in a different form, not a trust signal. A PDF need not exploit a software flaw to be dangerous; its QR code can simply move the victim to a malicious site.

QR codes themselves are not malicious. Legitimate sign-in and passkey processes can use them too. The warning sign is an unexpected message that asks you to scan a code and authenticate, especially for payroll, payments or account recovery—not the QR format alone.

Why a QR code can complicate email defenses

A mail gateway may inspect a PDF without following or fully evaluating the destination encoded in its image. Scanning the code on a personal phone also shifts the interaction away from the managed computer that received the email. The organization may have less visibility into the mobile browser, and the employee may perceive scanning as safer than clicking a link.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FINRA specifically warned that personal mobile devices used under bring-your-own-device arrangements can make this activity harder for conventional endpoint controls to monitor. That is a visibility gap, not proof that every QR code or phone-based sign-in is unsafe. Treat unsolicited QR codes as links: assess the context, use trusted sign-in routes, and report suspicious messages.

Why ordinary MFA could be intercepted

ONNX was reported to use an adversary-in-the-middle (AiTM) approach: the victim interacts with a fraudulent site while the attacker’s service relays information to the real identity provider. If the victim supplies a password and a phishable MFA code or approves a prompt, the attacker may use the relayed authentication to obtain a session. In that case, turning on MFA alone does not necessarily stop the attack.

This does not mean ONNX defeated every form of MFA. One-time codes sent by SMS, email or an authenticator, and push approvals, can be exposed to relay or social engineering. A stolen session token may also let an attacker access an account without repeating the full sign-in flow. Phishing-resistant methods are designed to bind authentication to the legitimate site, making a fake sign-in page much less useful. Microsoft identifies FIDO2 security keys and passkeys, Windows Hello for Business, and certificate-based authentication as phishing-resistant options in its phishing-resistant MFA guidance.

These methods materially reduce phishing risk, but they do not make account takeover impossible. Endpoint compromise, recovery-process abuse, token theft and policy misconfiguration remain separate concerns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why financial firms were attractive targets

The observed target set included banks, credit-union service providers, private-funding firms and other financial organizations—not just U.S. banks. FINRA’s warning addressed firms in its member population, while EclecticIQ described activity in EMEA and the Americas. Microsoft noted that financial services were heavily targeted because of the sensitivity of the data and transactions the sector handles.

A compromised Microsoft 365 mailbox can expose client information, deal documents, payroll data, payment instructions and internal communications. Attackers may use access to impersonate an employee, redirect vendor payments, send more phishing from a trusted account or seek a foothold for further intrusion, including ransomware activity.

What happened to the ONNX-branded operation

On November 22, 2024, Microsoft said it had seized 240 fraudulent websites associated with Egypt-based supplier Abanoub Nady, also known as MRxC0DER, who used the ONNX brand to sell do-it-yourself phishing kits. Microsoft’s announcement describes that disruption. It is not evidence that the exact 2024 storefront continues operating unchanged today, nor does a seizure establish that every related technique or criminal customer disappeared. The incident is best understood as a documented example of commercialized phishing and a reminder that other operators can reuse the same methods.

What Microsoft 365 administrators should prioritize

1. Require phishing-resistant sign-in for high-risk accounts

Prioritize administrators, finance and payroll staff, executives, and employees who approve payments or handle sensitive transactions. Use FIDO2 security keys, passkeys, Windows Hello for Business or certificate-based authentication where the organization’s identity setup supports them. Microsoft’s passkey and FIDO2 deployment guidance explains the Entra setup considerations. Plan enrollment, replacement keys, accessibility, travel and account recovery before making a stronger method mandatory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Apply access policy to the risk

Use Microsoft Entra Conditional Access to require stronger authentication for sensitive applications and higher-risk sign-ins. Where appropriate, make access depend on device compliance or other device-based conditions. Microsoft’s token guidance recommends layered mitigations that include phishing-resistant credentials, risk- and device-based access policies, and device-bound tokens where available. These controls should be designed around the organization’s architecture rather than treated as interchangeable switches.

3. Inspect suspicious messages and PDFs

Use email controls to inspect or quarantine suspicious PDF attachments, links and impersonation attempts. A blanket PDF block can disrupt payroll, lending, legal and client workflows, so consider sender reputation, sandboxing and targeted quarantine where a full block is impractical. Include QR-code attachments in realistic security exercises; training supports technical controls but cannot replace them.

4. Monitor identity and mailbox activity

Alert on unfamiliar sign-in locations or devices, anomalous access, unexpected authentication changes, suspicious OAuth consent, new mailbox rules or forwarding, and unusual sending activity. Maintain a response procedure that can disable or contain an account, revoke active sessions and refresh tokens where supported, and investigate mailbox access. Shorter token lifetimes may reduce some replay opportunities, but can add friction and are not a substitute for phishing-resistant authentication.

5. Address mobile access without assuming complete visibility

Mobile-device management and browser protections can improve oversight when employees access organizational resources from phones. Microsoft Intune can support managed mobile access, but it cannot guarantee visibility into every action on a personally owned device. Set clear access expectations for BYOD and provide a trusted way to reach work services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What employees should do

  • Do not use an unexpected email’s QR code to sign in, even when the message appears to concern salary, payroll or a work document.
  • Open Microsoft 365 through a known bookmark, the organization’s normal application portal or a trusted address entered directly.
  • Verify salary, payment, account-recovery and urgent document requests through a separate, known channel.
  • Never enter a password or MFA code on a page reached from an unsolicited QR code.
  • Report the email using your organization’s reporting process. If you entered credentials or approved a prompt, contact IT or security immediately rather than waiting for an alert.

Do not rely only on a page’s visual appearance or a quick glance at its address. Redirects, lookalike names and other tricks can make fraudulent destinations difficult to spot.

If someone interacted with a suspected phishing page

  1. Contain the account. Follow the incident plan to disable or otherwise limit access while the security team assesses the event.
  2. Reset credentials from a clean device. If the password was entered, treat it as exposed even if the user did not complete MFA.
  3. Revoke sessions and tokens where possible. A password change alone may not end an already authenticated session.
  4. Check authentication methods and account persistence. Review recent sign-ins, authentication details, registered devices, OAuth consent, mailbox rules, forwarding settings and sent mail; remove unauthorized changes and re-verify MFA methods if compromise is suspected.
  5. Find related messages and affected recipients. Search for the same lure and determine whether a compromised mailbox sent additional messages.
  6. Preserve evidence and coordinate notifications. Keep the original email, PDF, QR image, headers, destination information, timestamps and relevant logs. Involve payment-control teams and affected vendors where warranted.
  7. Report through appropriate channels. FINRA points firms to the FBI, IC3 and CISA reporting channels in its cybersecurity alert.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.