HomeSecurityRaccoonO365: Microsoft & Cloudflare dismantled phishing network

RaccoonO365: Microsoft & Cloudflare dismantle phishing network

Microsoft’s Digital Crimes Unit ( DCU) announced that it has partnered with Cloudflare to seize 338 domains associated with RaccoonO365 , a financially motivated threat group behind the eponymous phishing-as-a-service (Phaas) tool. This malicious service has stolen over 5,000 Microsoft 365 credentials from 94 countries since July 2024.

RaccoonO365 Microsoft Cloudflare phishing

Using a court order from the Southern District of New York, DCU disrupted the technical infrastructure of the malicious enterprise , cutting off the criminals’ access to victims. DCU’s Steven Masada emphasized that cybercriminals can cause significant damage with simple tools like RaccoonO365, making cybercrime accessible to many and putting millions of users at risk.

See also: Hackers stole customer data from Gucci, Balenciaga and Alexander McQueen

RaccoonO365: Remove phishing service

The takedown began on September 2, 2025, with further actions on September 3 and 4, which included seizing identified domains, placing warning pages, terminating relevant scripts, and suspending user accounts. The operation was completed on September 8.

Phishing kit function

RaccoonO365, tracked by Microsoft as Storm-2246, is promoted to cybercriminals through a subscription model, allowing phishing and credential harvesting attacks with minimal technical expertise. A 30-day subscription costs $355, while a 90-day plan is priced at $999.

The administrators claim that their tool is hosted on secure virtual private servers without hidden backdoors and is intended only for serious users.

Campaigns using RaccoonO365 have been active since September 2024, often impersonating trusted brands such as Microsoft and Adobe. Attackers send fake emails to solicit victims' Microsoft 365 usernames and passwords . These phishing emails often precede malware and ransomware attacks.

RaccoonO365: Microsoft & Cloudflare dismantle phishing network

A major consideration for security teams is the use of legitimate tools like Cloudflare Turnstile as a CAPTCHA. It also incorporates bot and automation detection to protect against phishing pages, ensuring that only intended targets can access them.

See also: New FileFix variant distributes StealC malware

RaccoonO365 allows customers to enter up to 9,000 email addresses target daily and uses techniques to bypass multi-factor authentication, allowing persistent access to victims’ systems. Recently, the group began promoting a new artificial intelligence-powered service, RaccoonO365 AI-MailCheck, which aims to enhance the sophistication and effectiveness of their attacks.

The mastermind behind RaccoonO365 is believed to be Joshua Ogundipe, based in Nigeria, who, along with his associates, has been promoting the tool on a Telegram channel with 850 members (taking in over $100,000 in cryptocurrency payments). Microsoft estimates that the team has sold around 100-200 subscriptions, although that number may be lower than the actual number.

The tech giant said it was able to attribute responsibility thanks to an operational security error that inadvertently exposed a secret cryptocurrency wallet. Ogundipe and four other accomplices remain at large, but Microsoft noted that a criminal complaint for Ogundipe has been sent to international law enforcement authorities.

Cloudflare, in its own analysis, stated that the removal of hundreds of domains and Worker accounts would send a strong message to other malicious actors who might abuse its infrastructure for malicious purposes.

See also: Signal: New APT28 attack distributes BeardShell and Covenant

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

RaccoonO365: Microsoft & Cloudflare dismantle phishing network

"Our response represents a strategic shift from reactive domain takedowns to a proactive, large-scale disruption aimed at dismantling the malicious actor on our platform," Cloudflare said.

Following the removal, the threat actors announced that they were “removing all old RaccoonO365 links,” urging customers who paid for a one-month subscription to switch to a new plan. The group also said it would compensate those affected by offering “one extra week of subscription” after the upgrade.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS