Microsoft shuts down Egyptian phishing operation

Microsoft shuts down Egyptian phishing operation
(Image: Solidcolours via Getty Images)

Microsoft dismantled 240 fraudulent websites linked to an Egyptian cybercrime operation selling do-it-yourself phishing kits, the software giant announced Thursday according to AFP. The US company’s Digital Crimes Unit identified Abanoub Nady, alias "MRxC0DER," as the alleged operator who misused the "ONNX" brand to market these tools.

The operation was among the top five providers of phishing kits by email volume in early 2024. The kits enabled sophisticated "adversary-in-the-middle" attacks that can bypass multifactor authentication, often using QR codes to lure victims. These attacks targeted financial firms and various sectors, causing significant harm, including theft of life savings.

A U.S. court granted Microsoft control of the malicious infrastructure, effectively ending the scheme. Microsoft filed the case jointly with the Linux Foundation, which owns the legitimate ONNX trademark. Active since 2017, the operation offered subscriptions and technical support for cybercriminals, contributing to millions of phishing attempts detected monthly.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to MAGHREB INSIDER.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.