Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Ice dance duo skated to AI music at the Olympics

VC Marcia Butcher, an associate of Epstein and founder of Day One, explains it herself.

Google sends student journalists’ personal and financial information to ICE

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » RACCOONO365 Phishing Network is dismantled as Microsoft, CloudFlare defeats 338 domains
Identity

RACCOONO365 Phishing Network is dismantled as Microsoft, CloudFlare defeats 338 domains

userBy userSeptember 17, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Microsoft’s Digital Crimes Unit said it has coordinated the seizure of 338 domains used by RACCOONO365, a financially motivated threat group that has been used since July 2024 to steal more than 5,000 Microsoft 365 qualifications from 94 countries.

“Using a court order granted by the Southern District of New York, the DCU seized 338 websites related to popular services, disrupted the technological infrastructure of its business and blocked access to criminal victims.”

“This case shows that cybercriminals don’t need to be refined to cause widespread harm. A simple tool like RACCOONO365 makes cybercrime accessible to virtually anyone, putting millions of users at risk.”

The initial stages of CloudFlare Takedown began on September 2, 2025 with additional actions occurring on September 3 and September 4. This includes banning all identified domains, placing a stroma Phish warning page before them, terminating relevant worker scripts, and suspending user accounts. The effort was completed on September 8th.

Audit and subsequent

Tracked by Windows Maker under the name Storm-2246, the Raccoono365 is sold to other cybercriminals under the subscription model, with little or no technical expertise and allows for large scale attachment of phishing and qualification harvesting attacks. The 30-day plan costs $355, while the 90-day plan costs $999.

The operators also claim that the tool is “built only for serious players and no budget freeloaders” hosted on a bulletproof virtual private server with no hidden background (unlike a bullet-like link, for example), and is “built only for serious players and not for low budget freeloaders.”

According to Morado, the campaign using RACCOONO365 has been active since September 2024. These attacks usually mimic trusted brands like Microsoft, Docusign, SharePoint, Adobe, Maersk, and other with fraudulent emails, making them click on pages that look like the victim’s Microsoft 365 user types and passwords. Phishing emails are often the predecessors of malware and ransomware.

The most annoying aspect from a defender’s perspective is using legitimate tools like CloudFlare Turnstile as Captcha and using CloudFlare worker scripts to implement bots and automation detection to protect your phishing pages.

Earlier this April, the Redmond-based company warned of several phishing campaigns that leverage tax-related themes to deploy malware such as Latrodectus, Ahkbot, Guloader and Bruteratel C4 (BRC4). The phishing page is distributed via RACCOONO365, and one such campaign is attributed to an early access broker called Storm-0249.

The phishing campaign covers more than 2,300 US organizations, including at least 20 US healthcare providers.

“With RACCOONO365’s services, customers can enter up to 9,000 target email addresses per day, and use sophisticated techniques to avoid multi-factor authentication protections to steal user credentials and gain sustained access to the victim’s system,” Microsoft said.

“Recently, the group has begun promoting the RACCOONO365 AI-Mailcheck, a new AI-powered service designed to enhance the spread and refined effectiveness of attacks.”

The mastermind behind Raccoono365 is rated Joshua Ogundipe, a Nigeria-based individual. He, along with his peers, promoted the tool on a strong 850-member telegram channel and received over $100,000 in cryptocurrency payments. The E-Crime group is believed to have sold about 100-200 subscriptions, but Microsoft warns that it is an underrated one.

CIS Build Kit

The tech giant said he was able to attribution courtesy of the operational security lapse, which inadvertently exposed a secret cryptocurrency wallet. Ogundipe and four other co-conspirators are currently on a large scale, but Microsoft noted that Ogundipe’s criminal referrals have been sent to international law enforcement.

CloudFlare said in its own analysis of the PHAAS service that takedowns of hundreds of domains and worker accounts are intended to increase operational costs and send warnings to other malicious actors who may abuse infrastructure for malicious purposes.

Since the upheaval, threat officials announced that they have “destroyed all legacy RACCOONO365 links,” urging customers who paid a month’s subscription to switch to a new plan. The group also said it would compensate those affected by offering a “one week additional subscription” after the upgrade.

“The response represents a strategic shift from a reactive, single-domain takedown to aggressive, massive disruption aimed at dismantling the operational infrastructure of actors on our platform,” Cloudflare said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHistory of Science: The tragic death of gene therapy that stalled the field for 10 years – September 17, 1999
Next Article Founder of DOJ Resentences Breachforums is a three-year founder for cybercrime and possession of CSAM
user
  • Website

Related Posts

North Korean agents impersonate experts on LinkedIn to infiltrate companies

February 10, 2026

Reynolds ransomware embeds BYOVD drivers that disable EDR security tools

February 10, 2026

Inside the rise of the digital parasite

February 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Ice dance duo skated to AI music at the Olympics

VC Marcia Butcher, an associate of Epstein and founder of Day One, explains it herself.

Google sends student journalists’ personal and financial information to ICE

Almost half of xAI’s founding team has now left the company.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.