Caffeine is a phishing-as-a-service (PhaaS) adversary-in-the-middle phishing kit first reported by Mandiant in 2022. Reporting from Sekoia.io and EclecticIQ indicates it is a prominent kit used to relay MFA challenges and steal Microsoft 365 credentials and 2FA/OTP codes in real time. EclecticIQ assessed with high confidence that ONNX Store is a rebranded version of Caffeine, based on overlaps in infrastructure and Telegram advertising, including a 2023 rebranding announcement from the former Caffeine Telegram channel.
The kit impersonates Microsoft 365 login pages and supports AiTM workflows that intercept authentication details and 2FA requests. Observed operations used PDF attachments containing embedded QR codes (“quishing”) to direct victims to phishing pages. EclecticIQ reported lures themed as Adobe or Microsoft 365, including HR-related pretexts such as salary updates and employee handbooks. The platform is operated through Telegram bots and support channels, enabling customers to receive stolen credentials and 2FA codes and manage phishing operations.
Caffeine/its ONNX Store rebrand uses Cloudflare CAPTCHA and proxying to hinder proactive scanning, sandboxing, and takedowns. EclecticIQ also reported encrypted or obfuscated JavaScript using Base64 and XOR, basic anti-debugging, collection of victim metadata via httbin[.]org and ipapi[.]co, and WebSockets for real-time exfiltration. Advertised add-on services included webmail for phishing delivery, cookie and 2FA token theft, redirect services using trusted domains, and bulletproof hosting/RDP.
Sekoia.io identified Caffeine as one of the most prominent phishing kits using Cloudflare to conceal infrastructure. EclecticIQ reported campaigns in February 2024 targeting financial institutions, including banks, private funding firms, and credit union service providers across EMEA and AMER. EclecticIQ assessed with high confidence that the Arabic-speaking actor MRxC0DER (mrxcoderxx) is likely the developer and maintainer of Caffeine, and with medium confidence that the ONNX Store rebrand is likely managed independently while MRxC0DER likely provides client support. Reported infrastructure and indicators included the suspected admin panel host Onnx[.]su and IP 5[.]181[.]156[.]247.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EclecticIQ analysts assess with high confidence that the ONNX Store phishing kit is very likely a rebranded version of the Caffeine phishing kit that Mandiant first discovered in 2022.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adversary-in-the-middle phishing kit (PhaaS) observed hiding infrastructure behind Cloudflare to make identification harder.
Phishing-as-a-Service phishing kit assessed as the predecessor/original branding of ONNX Store, with similar backend patterns and infrastructure/Telegram advertising overlaps; used for credential theft and supporting 2FA-bypass/AiTM-style phishing operations (as described via its rebranding into ONNX Store).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.