RacoonO365 is a phishing kit/phishing-as-a-service operation used to steal Microsoft 365 credentials via phishing pages impersonating Microsoft 365. Microsoft identified it as a new phishing kit and associated it with Storm-2246. The service was used by phishing actors prior to a coordinated takedown in October 2025, and Microsoft later reported seizing 338 domains tied to the operation. Supporting reporting states Microsoft used a court-authorized disruption strategy in 2025 against the RacoonO365 phishing service. Actors using RacoonO365 prior to its takedown were also observed leveraging RedVDS infrastructure, with medium-confidence assessment based on infrastructure overlap and tool usage. The content directly attributes credential theft targeting Microsoft 365 accounts to this service; no additional malware payload delivery or post-compromise capabilities are explicitly described in the provided material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RacoonO365 is a phishing service used to steal Microsoft 365 credentials.
A phishing-as-a-service offering used to conduct credential harvesting/account takeover against Microsoft email accounts; referenced as being used by actors who also leveraged RedVDS infrastructure prior to RacoonO365’s takedown (Oct 2025).
A phishing-as-a-service platform used to conduct credential phishing (notably against Microsoft 365/Office 365-style login workflows) and support account takeover/BEC operations.
A phishing kit and service used to create phishing pages targeting Microsoft 365 users, rented out to cybercriminals as a Phishing-as-a-Service (PhaaS) platform.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.