Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service
ID: 5c3bf2b2-619e-51ac-95b0-ef320ab0ca80
STIX ID: report--5c3bf2b2-619e-51ac-95b0-ef320ab0ca80
Feed Name: Bleeping Computer
Microsoft and Cloudflare disrupted RaccoonO365, a subscription-based Phishing-as-a-Service that sold phishing kits via a private Telegram channel and used CAPTCHA and anti-bot evasion to steal at least 5,000 Microsoft 365 credentials from 94 countries since July 2024; the kits targeted more than 2,300 U.S. organizations (including healthcare) and the stolen credentials and cookies were used for financial fraud, extortion, and initial access. Authorities seized 338 websites and Worker accounts, Microsoft identified a likely operator and estimated at least $100,000 in cryptocurrency revenue, and a criminal referral has been sent to international law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
