Raccoon0365 is a phishing-as-a-service (PhaaS) operation associated with large-scale credential theft campaigns. It has been described as a subscription-based phishing service and has been linked to infrastructure used to host phishing pages and collect stolen account data. The operation has adopted browser-in-the-browser (BITB) functionality, enabling phishing workflows that imitate legitimate authentication windows and improve the realism of login lures. This capability is consistent with attempts to capture credentials and multi-factor authentication material in real time and to facilitate account compromise. Raccoon0365 is part of the broader criminal ecosystem that productizes phishing tradecraft for customers, lowering the barrier to entry for less technically capable operators. Its activity aligns with identity-focused intrusion methods centered on phishing rather than malware deployment. High-confidence reporting ties the operation to credential theft and cryptocurrency-linked profits, indicating a financially motivated cybercriminal service model. Its infrastructure was significant enough to be the subject of coordinated disruption actions, including the seizure and dismantling of a large number of phishing-related domains and associated infrastructure. Based on the available facts, Raccoon0365 is best characterized as a financially motivated cybercriminal phishing service with initial-access and credential-harvesting capabilities, including the use of spoofed authentication interfaces and session-oriented phishing techniques associated with modern BITB-enabled campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Raccoon0365 is a phishing-as-a-service provider that incorporated browser-in-the-browser (BITB) techniques into its offerings, making advanced phishing attacks more accessible to cybercriminals. Its infrastructure was dismantled by Cloudflare and Microsoft.
Raccoon0365 is known for operating a phishing subscription service, facilitating credential theft and profiting from stolen data and cryptocurrency. Microsoft led a major crackdown by seizing domains associated with this threat actor.
Raccoon0365 is known for operating a phishing subscription service, facilitating credential theft and profiting from stolen data and cryptocurrency. Microsoft led a major crackdown by seizing domains associated with this threat actor.
Raccoon0365 is known for operating a phishing subscription service, facilitating credential theft and profiting from stolen data and cryptocurrency. Microsoft led a major crackdown by seizing domains associated with this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.