logo

Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service

ID: 5c3bf2b2-619e-51ac-95b0-ef320ab0ca80

STIX ID: report--5c3bf2b2-619e-51ac-95b0-ef320ab0ca80

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-09-17

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Microsoft and Cloudflare disrupted RaccoonO365, a subscription-based Phishing-as-a-Service that sold phishing kits via a private Telegram channel and used CAPTCHA and anti-bot evasion to steal at least 5,000 Microsoft 365 credentials from 94 countries since July 2024; the kits targeted more than 2,300 U.S. organizations (including healthcare) and the stolen credentials and cookies were used for financial fraud, extortion, and initial access. Authorities seized 338 websites and Worker accounts, Microsoft identified a likely operator and estimated at least $100,000 in cryptocurrency revenue, and a criminal referral has been sent to international law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.