Shay Colson, CISSP’s Post

View profile for Shay Colson, CISSP, graphic

Cybersecurity for Growth-Stage Companies and Investors

There are lots of clever tricks in here that make stopping this #quishing #phishing attack hard for us on the defender's side: 1. "The emails impersonate human resources (HR) departments, using salary updates as lures to open the PDFs, which are themed after Adobe or Microsoft." People love to click these kind of updates, and Adobe / Microsoft themes are legit enough. Plus, because it's a PDF, just looking for QR code images isn't going to stop them. 2. "Scanning the QR code on a mobile device bypasses phishing protections on the targeted organizations, taking victims to phishing pages that mimic the legitimate Microsoft 365 login interface." This means you've got no record of a "click" in the traditional sense, and you've got no network telemetry of these connections going out - essentially, the defenders are blind to user action here. 3. "The victim is prompted to enter their login credentials and 2FA token on the fake login page, and the phishing site captures these details in real-time. The stolen credentials and 2FA token are immediately relayed to the attackers via WebSockets, allowing them to hijack the target's account before the authentication and MFA-validated token expires." Are your defenses going to move this fast? I doubt it. Meanwhile, the attackers are running it all through a Telegram bot, and covering their tracks: "The ONNX phishing kit also uses encrypted JavaScript code that decrypts itself during page load, adding a layer of obfuscation to evade detection by anti-phishing tools and scanners." "Additionally, ONNX uses Cloudflare services to prevent its domains from being taken down, including an anti-bot CAPTCHA and IP proxying." "There is also a bulletproof hosting service to ensure that the operations aren't interrupted by reports and takedowns, as well as remote desktop protocol (RDP) services for managing the campaigns securely." This should give you a real sense of how sophisticated email attacks are happening today. Make sure your defenses are up to snuff!

ONNX phishing service targets Microsoft 365 accounts at financial firms

ONNX phishing service targets Microsoft 365 accounts at financial firms

bleepingcomputer.com

To view or add a comment, sign in

Explore topics