Phishing-as-a-Service: The Microsoft Smackdown

By: Ben Fielding | Estimated Reading Time: 3 minutes

What It Means for Your Business

Phishing scams are among the most persistent and damaging threats to businesses, tricking people into handing over information like passwords, payment details, and more. This digital pick-pocketing has evolved into a full-blown, very profitable industry, with cybercriminals offering Phishing-as-a-Service (PaaS) kits to help other criminals create convincing phishing campaigns.

One major player in this ecosystem, an Egypt-based group known as ONNX, has been dealt a significant blow by the Microsoft Digital Crimes Unit (DCU). Microsoft recently seized 240 fraudulent websites operated by ONNX, disrupting their operations and sending a strong message to cybercriminals.

Hereโ€™s what happened, why it matters, and what your business can do to stay ahead of these evolving threats.


What Is Phishing-as-a-Service?

Phishing is a cyberattack where criminals impersonate trusted entitiesโ€”like banks or popular platformsโ€”to trick people into sharing sensitive data. Phishing scams can result in devastating consequences, including:

  • Financial losses.
  • Compromised systems.
  • Data breaches.

Phishing-as-a-Service takes this a step further. Groups like ONNX develop and sell phishing kits, which are essentially plug-and-play tools for creating phishing campaigns. These kits often include:

  • Templates for fake emails and websites.
  • Tools to bypass multi-factor authentication (MFA).
  • Advanced techniques, like QR code phishing (quishing).

With PaaS, even low-skilled criminals can launch sophisticated phishing attacks. ONNXโ€™s phishing kits alone were responsible for a significant portion of the tens of millions of phishing emails targeting Microsoft accounts each month.


How Microsoft Disrupted ONNX

Microsoftโ€™s DCU identified ONNX as one of the top five phishing kit providers by email volume in 2024. To combat their operations, Microsoft seized 240 malicious websites used to distribute ONNXโ€™s phishing kits. These websites were key to promoting and selling the kits to other criminals.

Who Is Behind ONNX?

Microsoft has publicly named Abanoub Nady, also known as โ€œMRxC0DER,โ€ as the individual responsible for ONNX. Nady has been tied to phishing operations since 2017 and is a well-known figure in the PaaS ecosystem.

Operating under a tiered subscription model, ONNX offered plans ranging from basic to enterprise, complete with setup guides and video tutorials. The group even promoted their services on Telegram, making it easy for criminals to get started.

The Rise of โ€œQuishingโ€

ONNXโ€™s phishing kits included a technique known as QR code phishing, or quishing. This method involves embedding QR codes in phishing emails that redirect victims to fake websites. These sites often ask for personal or payment information.

Quishing is particularly dangerous because:

  • It can bypass traditional email security systems.
  • People are less suspicious of QR codes compared to email links.

The Ongoing Battle Against Phishing

While Microsoftโ€™s takedown of ONNX is a significant step forward, itโ€™s far from the end of phishing threats. As Assistant General Counsel for Microsoftโ€™s DCU, Steven Masada, explained:

โ€œNo disruption is complete in one action. Effectively combating cybercrime requires persistence and ongoing vigilance to disrupt new malicious infrastructure.โ€

Cybercriminals are highly adaptable, and when one operation is shut down, others often step in to fill the void. This means businesses must remain vigilant and proactive in defending against phishing threats.


How to Protect Your Business from Phishing

The fight against phishing requires a combination of technology, training, and vigilance. Here are some steps you can take to keep your business safe:

1. Invest in Strong Security Tools

  • Use advanced email filtering systems to block phishing emails.
  • Implement endpoint protection solutions to detect and prevent attacks.
  • Enable multi-factor authentication (MFA) to add an extra layer of security.

Find out more about cybersecurity services from Nxt Gen IT.

2. Train Your Team

  • Educate employees about how phishing works and what to look for.
  • Conduct regular phishing simulations to test and reinforce awareness.
  • Encourage staff to report suspicious emails immediately.

Find out more about cyber awareness training from Nxt Gen IT.

3. Monitor for Emerging Threats

Stay informed about the latest phishing tactics, like quishing, and update your defences accordingly.

4. Implement a Response Plan

Prepare your team to act quickly if a phishing attack occurs. This includes isolating affected systems, notifying key stakeholders, and securing compromised accounts.


Looking Ahead

Microsoftโ€™s takedown of ONNX is a major victory, but the battle against phishing is ongoing. Cybercriminals are constantly evolving their methods, and businesses must adapt to stay protected.

By leveraging tools like advanced email filtering, training employees, and monitoring for new threats, your business can build a strong defence against phishing scams.


Need Help Strengthening Your Defences?

At Nxt Gen IT, we specialise in protecting businesses from cyber threats like phishing. From deploying cutting-edge security tools to training your team, weโ€™ll help you stay one step ahead of cybercriminals.

Nxt Steps

Contact us today to learn how we can secure your business and give you peace of mind.