RaccoonO365 is a phishing-as-a-service (PhaaS) platform focused on stealing Microsoft 365 credentials. It provides subscription-based phishing kits and infrastructure that generate fake Microsoft login pages and Microsoft 365 sign-in portals, and is described as enabling low-skill criminals to conduct credential theft at scale. The service has been used to deliver phishing pages via links and QR codes, including in tax-themed campaigns, and victims were in some cases routed through a CAPTCHA page before reaching the fake Microsoft O365 login portal. Reported impersonated brands include Microsoft, DocuSign, Adobe, SharePoint, and Maersk.
The platform targeted users of Microsoft 365 and was used against corporate, financial, educational, and healthcare organizations. Microsoft reported that since July 2024, RaccoonO365 kits were used to steal at least 5,000 Microsoft credentials across 94 countries, and one report cited targeting of more than 2,300 U.S. organizations, including more than 20 healthcare systems. The service was described as capable of targeting up to 9,000 email addresses per day. Multiple reports state it supported techniques to bypass or circumvent multifactor authentication.
Operationally, RaccoonO365 was sold via Telegram on a subscription basis, with reporting citing pricing of about $365 per month and Telegram groups with roughly 835-850 members. Microsoft reported the operation accrued more than $100,000 in payments. Fraudulent portals were reportedly hosted on Cloudflare using stolen or fraudulent credentials. Microsoft and Cloudflare disrupted the operation in September by seizing 338 associated websites/domains. Microsoft and Health-ISAC also pursued legal action against the operators.
The operation has been linked to Nigerian actors. Microsoft identified Joshua Ogundipe as a leading force behind RaccoonO365 and alleged he wrote much of the code and managed marketing and sales. Nigerian authorities also arrested Okitipi Samuel in connection with operating or developing the service, with additional arrests reported. RaccoonO365 has been associated with downstream harms including business email compromise, unauthorized access to email platforms, data breaches, and financial losses.
A reported indicator directly associated with RaccoonO365 infrastructure is the domain shareddocumentso365cloudauthstorage[.]com, which Microsoft observed in QR-code phishing campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The FBI said the phishing kit was backed by an online marketplace called W3LLSTORE that offered up individuals’ login details and credentials for remote desktops.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit/service referenced as part of Microsoft disruption operations; discussed as adjacent to Tycoon 2FA within the impersonation-for-hire ecosystem.
A cybercrime service used to support large-scale phishing operations; referenced as infrastructure/tooling used by RedVDS customers and previously taken down by Microsoft.
A phishing-as-a-service operation used to steal Microsoft 365 credentials at scale.
Phishing-as-a-service platform used to generate fake Microsoft 365 login pages for credential harvesting, targeting organizations globally.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.