ONNX Bot Tool Compromises Microsoft 365 Accounts, Circumvents 2FA Security

Researchers have identified a complex phishing operation known as the ONNX Store, which equips cybercriminals with cutting-edge tools to compromise Microsoft 365 accounts.

Worryingly, these tools include methods to circumvent two-factor authentication (2FA), a key security layer that many organizations depend on to safeguard sensitive data. This discovery highlights the critical importance for corporate security teams to enhance their defenses against phishing attacks.

How the Attack Works

According to Kaspersky’s findings, the ONNX Store’s phishing tools have been employed in targeted attacks against employees in the financial sector.

The attack typically begins with an email that appears to be from the victim’s HR department, discussing remuneration. This email includes a PDF attachment containing a QR code, which prompts the recipient to scan it to access a “secure document” with essential salary details.

The attackers aim to have the victim open the link on a personal smartphone, which may lack the phishing protection found on work devices. Scanning the QR code leads the victim to a fake Microsoft 365 login page, where they are asked to enter their username, password, and 2FA code.

This login information is instantly transmitted to the attackers via the WebSocket protocol, enabling them to swiftly take control of the victim’s account. Once inside, the attackers can carry out business email compromise (BEC) schemes and other malicious activities.

Phishing-as-a-Service: A New Era of Cybercrime

The ONNX Store operates mainly through the Telegram messaging app, offering its phishing tools as a subscription service. The cost is relatively low, with subscriptions for stealing Microsoft 365 credentials priced at $200 per month, or $400 if they include a 2FA bypass.

This affordability makes the service accessible to less sophisticated criminals, broadening the range of potential attackers.

The phishing-as-a-service model is particularly concerning because it reduces the technical barriers to entry for cybercrime, allowing a larger group of criminals to use powerful tools. This widespread availability poses a significant threat to organizations globally.

Strengthening Your Organization’s Defenses

In light of the growing accessibility of advanced phishing tools, organizations must take proactive measures to protect themselves.

Here are some key strategies:

  • Adopt Stronger 2FA Methods: Consider using FIDO U2F hardware tokens like YubiKeys or passkeys for 2FA. These tools are effective against even the most sophisticated phishing attempts.
  • Implement Comprehensive Security Solutions: Ensure that all corporate devices, including mobile phones and tablets, are equipped with robust security solutions that offer anti-phishing protection.
  • Enhance Employee Security Training: Regularly conduct security awareness training to help employees identify and handle suspicious emails. Interactive tools, like the Kaspersky Automated Security Awareness Platform, can be valuable resources for this training.

By implementing these strategies, organizations can better defend against the evolving threats posed by phishing-as-a-service platforms like the ONNX Store.

More Articles & Posts