Microsoft takes down Nigerian trash pandas (Credit Image: AI-generated by Ian Murphy using Microsoft Designer)Microsoft has seized 338 domains associated with the cybergang RaccoonO365, also known as Storm-2246. It has also named the leader of the group as Joshua Ogundipe. RacoonO365 is a subscription-based phishing service that has sold phishing kits to cybercriminals since 2024 via its private Telegram channel. To date, some 5,000 Microsoft 365 accounts from 94 countries are believed to have been compromised by these phishing kits.

The kits were available at prices from just over $330 to $999. The gang, led by Ogundipe, are believed to have made over $100,000 from its customers. Each kit can be used multiple times, which makes them a low-cost and lucrative tool for cybercriminals.

Interestingly, the number of phishing kits sold is far less than the number of members in the Telegram channel. That disparity raises the question of whether the investigators have managed to track all the subscriptions.

Steven Masada, assistant general counsel at Microsoft's Digital Crimes Unit (Image Credit: LinkedIn)
Steven Masada, assistant general counsel at Microsoft’s Digital Crimes Unit

Steven Masada, assistant general counsel at Microsoft’s Digital Crimes Unit, said, “Using a court order granted by the Southern District of New York, the DCU seized 338 websites associated with the popular service, disrupting the operation’s technical infrastructure and cutting off criminals’ access to victims.”

Microsoft seized the websites with assistance from Cloudflare. Also part of this operation was Health-ISAC. It took part because over 20 US healthcare organisations had been targeted by the RacoonO365 phishing kits.

How do the RacoonO365 kits work?

The phishing kits allowed cybercriminals to create legitimate emails and websites using Microsoft’s branding. Victims were then directed to those sites to log in using their Microsoft 365 credentials, which were then captured by the cybercriminals. Other types of activity include the installation of malware such as remote access trojans (RATs) and downloaders.

Once credentials had been harvested and additional malware deployed, the details were then sold to other criminals. These then used them to further compromise victims and, through them, organisations and businesses.

Earlier this year, the Microsoft DCU tracked a campaign that targeted users who were planning to file their taxes online. It observed RacoonO365 and other malicious actors, using phishing kits to send thousands of emails to potential victims in the United States.

In particular, it identified emails sent to 2,300 US organisations over a two-week period from February 12 to February 28. The victims were mainly companies involved in engineering, IT and consulting. The emails contained a QR code and a PDF that the victims needed to sign. Following the QR code took victims to one of the seized sites that was owned by RacoonO365.

To make it harder to track the campaign, the URLs used the email address of the recipient. That meant each URL was unique, making the pattern much harder to spot.

Why has Microsoft acted now?

According to the DCU blog, Microsoft is concerned about the speed with which RacoonO365 is evolving. It has seen regular upgrades issued and demand is increasing. The phishing kit allows users to enter as many as 9,000 target email addresses per day. That means attackers can use a list of stolen email addresses and automate their phishing campaigns.

The blog also states that the kits “employ sophisticated techniques to circumvent multi-factor authentication protections to steal user credentials and gain persistent access to victims’ systems.”

Perhaps the most serious concern, however, is that the group had started to advertise a new AI-powered service. Called RaccoonO365 AI-MailCheck, the DCU says it is “designed to scale operations and increase the sophistication, and effectiveness, of attacks.”

Enterprise Times: What does this mean?

Cybergangs have been using the subscription-based as-a-service approach of distributing malware for years. They recognised a way to build an entire infrastructure that often has all the resilience, if not more, than enterprise IT. It also allows for a wider and more profitable infrastructure where people can concentrate on what they are good at and earn a good living.

The RacoonO365 Phishing-as-a-Service (PHaaS) kits are just the latest example of this. What it also shows, as called out by the DCU, is the speed with which the operators updated the kits and evolved new offerings.

Despite seizing 338 domains, it will be interesting to see if RacoonO365 goes away. The likelihood is that it will resurface under a different name or do a deal to merge its code with another group. As we all know, trash pandas are hard to get rid of once they see you as a food source.

Previous articleUnit4 appoints MD of Unit4 Financials by Coda
Next articleRipjar targets US growth after success
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here