Wednesday, January 22, 2025
HomeHacksTelegram Bot Selling Phishing Tools to Bypass 2FA & Hack Microsoft 365...

Telegram Bot Selling Phishing Tools to Bypass 2FA & Hack Microsoft 365 Accounts

Published on

SIEM as a Service

Follow Us on Google News

A newly discovered phishing marketplace, ONNX Store, empowers cybercriminals to launch sophisticated attacks against Microsoft 365 and Office 365 environments. The platform provides tools to circumvent robust 2FA safeguards, enabling threat actors to compromise accounts with increased efficiency. 

Corporate security teams must prioritize anti-phishing defenses to mitigate the risk of successful attacks, data breaches, and financial loss resulting from this advanced threat. 

Cybercriminals are leveraging ONNX Store phishing tools to target financial institutions. The attack vector involves deceptive emails disguised as HR communications about remuneration, enticing victims to open attached PDFs containing malicious QR codes. 

Scanning these codes redirects users to phishing sites designed to mimic legitimate login pages, enabling attackers to steal credentials and bypass 2FA, granting unauthorized access to sensitive systems. 

The fake Microsoft login page prompts victims to enter their credentials and a one-time 2FA code.

A phishing attack leverages email with a PDF attachment containing a QR code, enticing victims to scan it for supposed “vital salary information,” which redirects users to a fraudulent Microsoft 365 login page designed to harvest credentials and 2FA codes. 

Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Access

By targeting personal smartphones, the attack circumvents potential corporate anti-phishing defenses, increasing the likelihood of successful credential theft. 

The attacks leverage WebSocket’s real-time communication to rapidly exfiltrate stolen credentials and one-time 2FA codes, while attackers embed phishing kits within malicious emails to deceive victims into revealing sensitive information. 

According to Kaspersky, upon successful credential capture, the WebSocket protocol swiftly transmits the data to the attacker’s infrastructure. 

With immediate access to both credentials and a valid 2FA code, attackers can promptly infiltrate victim accounts, compromising email correspondence and enabling subsequent attacks like Business Email Compromise (BEC). 

ONNX Store operates a phishing-as-a-service platform centered on Telegram, employing bots to automate all user interactions. 

This infrastructure leverages Telegram as a command-and-control hub for phishing campaigns, streamlining the distribution of phishing kits and the management of compromised accounts through automated processes. 

Cybercriminals can now outsource phishing attacks by subscribing to specialized services, which offer a range of tools and infrastructure for crafting and executing phishing campaigns at low costs. 

Subscribers gain access to pre-engineered phishing kits targeting specific platforms like Microsoft 365, including options to bypass two-factor authentication, which lowers the barrier of entry for cybercriminals, enabling even low-level actors to launch sophisticated attacks and monetize stolen credentials. 

To mitigate advanced phishing risks, implement FIDO U2F hardware tokens or passkeys for robust 2FA, deploy comprehensive security solutions with anti-phishing capabilities across all devices, and conduct regular, interactive security awareness training to enhance employee vigilance against sophisticated phishing tactics. 

Download Free Cybersecurity Planning Checklist for SME Leaders (PDF) – Free Download

Kaaviya
Kaaviya
Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Latest articles

SQL Injection Vulnerability in Microsoft’s DevBlogs Lets Hackers Injecting Malicious SQL

In a recent discovery, a security researcher uncovered a critical SQL injection vulnerability on...

Three New ICS Advisories Released by CISA Detailing Vulnerabilities & Mitigations

The Cybersecurity and Infrastructure Security Agency (CISA) announced three new Industrial Control Systems (ICS)...

Security Researchers Discover Critical RCE Vulnerability, Earned $40,000 Bounty

Cybersecurity researchers Abdullah Nawaf and Orwa Atyat, successfully escalated a limited path traversal vulnerability...

IBM i Access Client Solutions Might Be Leaking Your Passwords

A potential security flaw in IBM i Access Client Solutions (ACS) has raised serious...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

SQL Injection Vulnerability in Microsoft’s DevBlogs Lets Hackers Injecting Malicious SQL

In a recent discovery, a security researcher uncovered a critical SQL injection vulnerability on...

Microsoft Rolls Out New Administrator Protection Feature Under Windows Security

Microsoft has announced the release of Windows 11 Insider Preview Build 27774 to the...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....