What It Means for Your Business
Phishing scams are among the most persistent and damaging threats to businesses, tricking people into handing over information like passwords, payment details, and more. This digital pick-pocketing has evolved into a full-blown, very profitable industry, with cybercriminals offering Phishing-as-a-Service (PaaS) kits to help other criminals create convincing phishing campaigns.
One major player in this ecosystem, an Egypt-based group known as ONNX, has been dealt a significant blow by the Microsoft Digital Crimes Unit (DCU). Microsoft recently seized 240 fraudulent websites operated by ONNX, disrupting their operations and sending a strong message to cybercriminals.
Hereโs what happened, why it matters, and what your business can do to stay ahead of these evolving threats.
What Is Phishing-as-a-Service?
Phishing is a cyberattack where criminals impersonate trusted entitiesโlike banks or popular platformsโto trick people into sharing sensitive data. Phishing scams can result in devastating consequences, including:
- Financial losses.
- Compromised systems.
- Data breaches.
Phishing-as-a-Service takes this a step further. Groups like ONNX develop and sell phishing kits, which are essentially plug-and-play tools for creating phishing campaigns. These kits often include:
- Templates for fake emails and websites.
- Tools to bypass multi-factor authentication (MFA).
- Advanced techniques, like QR code phishing (quishing).
With PaaS, even low-skilled criminals can launch sophisticated phishing attacks. ONNXโs phishing kits alone were responsible for a significant portion of the tens of millions of phishing emails targeting Microsoft accounts each month.
How Microsoft Disrupted ONNX
Microsoftโs DCU identified ONNX as one of the top five phishing kit providers by email volume in 2024. To combat their operations, Microsoft seized 240 malicious websites used to distribute ONNXโs phishing kits. These websites were key to promoting and selling the kits to other criminals.
Who Is Behind ONNX?
Microsoft has publicly named Abanoub Nady, also known as โMRxC0DER,โ as the individual responsible for ONNX. Nady has been tied to phishing operations since 2017 and is a well-known figure in the PaaS ecosystem.
Operating under a tiered subscription model, ONNX offered plans ranging from basic to enterprise, complete with setup guides and video tutorials. The group even promoted their services on Telegram, making it easy for criminals to get started.
The Rise of โQuishingโ
ONNXโs phishing kits included a technique known as QR code phishing, or quishing. This method involves embedding QR codes in phishing emails that redirect victims to fake websites. These sites often ask for personal or payment information.
Quishing is particularly dangerous because:
- It can bypass traditional email security systems.
- People are less suspicious of QR codes compared to email links.
The Ongoing Battle Against Phishing
While Microsoftโs takedown of ONNX is a significant step forward, itโs far from the end of phishing threats. As Assistant General Counsel for Microsoftโs DCU, Steven Masada, explained:
โNo disruption is complete in one action. Effectively combating cybercrime requires persistence and ongoing vigilance to disrupt new malicious infrastructure.โ
Cybercriminals are highly adaptable, and when one operation is shut down, others often step in to fill the void. This means businesses must remain vigilant and proactive in defending against phishing threats.
How to Protect Your Business from Phishing
The fight against phishing requires a combination of technology, training, and vigilance. Here are some steps you can take to keep your business safe:
1. Invest in Strong Security Tools
- Use advanced email filtering systems to block phishing emails.
- Implement endpoint protection solutions to detect and prevent attacks.
- Enable multi-factor authentication (MFA) to add an extra layer of security.
Find out more about cybersecurity services from Nxt Gen IT.
2. Train Your Team
- Educate employees about how phishing works and what to look for.
- Conduct regular phishing simulations to test and reinforce awareness.
- Encourage staff to report suspicious emails immediately.
Find out more about cyber awareness training from Nxt Gen IT.
3. Monitor for Emerging Threats
Stay informed about the latest phishing tactics, like quishing, and update your defences accordingly.
4. Implement a Response Plan
Prepare your team to act quickly if a phishing attack occurs. This includes isolating affected systems, notifying key stakeholders, and securing compromised accounts.
Looking Ahead
Microsoftโs takedown of ONNX is a major victory, but the battle against phishing is ongoing. Cybercriminals are constantly evolving their methods, and businesses must adapt to stay protected.
By leveraging tools like advanced email filtering, training employees, and monitoring for new threats, your business can build a strong defence against phishing scams.
Need Help Strengthening Your Defences?
At Nxt Gen IT, we specialise in protecting businesses from cyber threats like phishing. From deploying cutting-edge security tools to training your team, weโll help you stay one step ahead of cybercriminals.
Nxt Steps
Contact us today to learn how we can secure your business and give you peace of mind.
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
