ONNX Store is a phishing-as-a-service platform associated with credential phishing and business email compromise activity targeting Microsoft 365 accounts. It has been observed using quishing techniques in which QR codes embedded in PDF attachments direct victims to counterfeit Microsoft 365 login pages. The operation supports adversary-in-the-middle phishing workflows that can capture credentials and intercept multi-factor authentication interactions, enabling theft of both credentials and active session data. Reporting has also linked ONNX Store to encrypted JavaScript and hosting practices intended to delay takedowns and hinder detection. ONNX Store has been described as a revamped version of the Caffeine phishing-as-a-service platform based on overlapping tactics, techniques, and procedures. Its activity has been noted against FINRA member firms, indicating a focus on organizations using Microsoft 365 in the financial sector.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting phishing and business email compromise campaigns against Microsoft 365 accounts using quishing, QR codes embedded in PDFs, adversary-in-the-middle phishing pages, and 2FA interception.
CTI Roundup: Busy Days for Threat Actors ONNX Store, Boolka, & SneakyChef | Tanium
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.