Skip to content

Microsoft and Cloudflare Take Down RaccoonO365, a Sophisticated Phishing Service

RaccoonO365's advanced tactics bypassed multi-factor authentication. Its takedown is a significant victory against cybercrime.

there was a room in which people are sitting in the chairs,in front of a table looking into the...
there was a room in which people are sitting in the chairs,in front of a table looking into the laptop and doing something,beside them there are many flee xi in which different advertisements are present which different text.

Microsoft and Cloudflare Take Down RaccoonO365, a Sophisticated Phishing Service

Microsoft and Cloudflare have collaborated to dismantle RaccoonO365, a notorious phishing service that targeted users worldwide. Joshua Ogundipe, a Nigerian national, has been identified as the mastermind behind this operation.

RaccoonO365, a subscription-based phishing kit, mimicked Microsoft 365 branding to create convincing fake emails, attachments, and websites. Its sophisticated tactics allowed it to steal at least 5,000 Microsoft 365 credentials across 94 countries. The service was so advanced that it offered techniques to bypass multi-factor authentication protections and even included an AI-backed feature to scale campaigns, targeting up to 9,000 email addresses daily.

The group behind RaccoonO365 has been active for over a year, earning at least $100,000 in cryptocurrency from subscriptions. However, Microsoft obtained a court order to seize 338 websites associated with the service, and Cloudflare took down hundreds of domains and accounts linked to the group. The latter also spoofed other brands like Adobe and Maersk to deceive users.

The takedown of RaccoonO365 is a significant blow to cybercriminals relying on this sophisticated phishing service. Joshua Ogundipe's identification as the leading force behind RaccoonO365 may lead to further investigations and potential arrests. Users are advised to remain vigilant against phishing attempts and enable all available security measures to protect their Microsoft 365 credentials.

Read also:

Latest