Storm-2246 is a financially motivated cybercriminal operation associated with RaccoonO365, a phishing-as-a-service platform focused on stealing Microsoft 365 credentials. The operation has been linked to Nigeria, and identified leadership has been attributed to Joshua Ogundipe. Storm-2246 marketed subscription-based phishing kits that impersonate Microsoft communications and branding, lowering the barrier to entry for other criminals and enabling large-scale credential harvesting. The service was sold and supported through Telegram, with operators reportedly handling development, sales, and customer support as distinct roles within the enterprise. The group’s activity has been observed at global scale, with victims spanning dozens of countries and campaigns targeting thousands of organizations. Reported targeting has included U.S. organizations and the healthcare sector, where credential theft can lead to operational disruption and exposure of sensitive data. Storm-2246’s phishing kits were described as evolving rapidly, including regular feature upgrades, support for high-volume targeting, and techniques intended to circumvent multi-factor authentication. The operation also advertised an AI-enabled service to improve phishing effectiveness. Storm-2246’s core tradecraft centers on initial access through spoofed Microsoft-themed phishing lures and credential theft against cloud identities. Its business model aligns with cybercrime enablement: providing phishing infrastructure and tooling to subscribers who can conduct attacks at scale. High-confidence reporting supports phishing-based initial access, credential theft, spoofing of trusted brands, and defense-evasion measures aimed at bypassing authentication protections. The actor’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.