Microsoft's Fight Against phishing-As-A-Service
This particular article opened my eyes to an entirely new part of the cybercriminal world that, while I'm not surprised it exists, was entirely new information to me.
Apparently, as far back as 2017 Microsoft has been keeping tabs on Abanoub Nady (also known as MRxC0DER) who has been selling do-it-yourself phishing kits and supplying continued support for them in a phishing-As-A-Service (PhaaS) subscription plan. It seems Abanoub Nady had also been illegitimately using the trademark "ONNX" too.
The phishing kits were designed for large scale, coordinated attacks and where among the five most used phishing kits in the first half of 2024, per Microsoft Digital Defense Report - article (Microsoft Digital Defense Report 2024 - direct link).
I highly recommend reading more about the defense report at least, as a student I found it to be really insightful and interesting to skim through. I'd like to circle back when I have more time and give it a proper read through though. I'm sure I could learn tons more about the industry and different attack vectors reading through a comprehensive report like that.
Original Article: Microsoft Seizes 240 Domains Used By phishing-As-A-Service (PhaaS) Platform
Comments
Post a Comment