Executive Summary
In July 2024, Microsoft’s Digital Crimes Unit, in collaboration with law enforcement and cybersecurity partners, led a takedown of RaccoonO365—a subscription-based phishing-as-a-service platform operated by the threat group Storm-2246. Over 338 domains linked to RaccoonO365 were seized after being used to steal more than 5,000 Microsoft credentials across 94 countries since July 2024. The group’s kits, leveraging sophisticated evasion techniques and authentic-looking Microsoft branding, enabled cybercriminals to mount tax-themed and healthcare-targeted phishing campaigns, with sessions often bypassing multifactor authentication to harvest both passwords and session cookies.
The breadth and pace of RaccoonO365’s operations highlight the commoditization and professionalization of cybercrime. This incident signals a shift towards scalable, as-a-service attack tools, increasing risks to organizations globally. Security teams must rapidly adapt to evolving TTPs and plug new identity-driven attack pathways, especially as phishing toolkits grow in accessibility and sophistication.
Why This Matters Now
This incident underscores the growing threat from phishing-as-a-service operations, which lower the technical barrier for cybercriminals and drive exponential growth in credential theft attacks. As such infrastructures proliferate, organizations face urgent pressure to strengthen identity protections, email security, and cross-border legal collaboration to counter rapidly evolving and highly scalable cybercrime models.
Attack Path Analysis
Attackers initiated the campaign by sending phishing emails containing malicious links or attachments that redirected users to fraudulent Microsoft O365 login portals, where credentials and session cookies were harvested. Stolen credentials enabled unauthorized access to victim accounts, potentially allowing privilege escalation if higher-level accounts or tokens were compromised. With authorized access, attackers could move laterally to other cloud services or internal resources if additional privileges were available. Compromised environments were used for ongoing command and control via harvested sessions, possibly evading detection through dynamic traffic routing and anti-analysis methods. Attackers exfiltrated data—primarily credentials and session tokens—using web-based channels under the guise of legitimate O365 activity. The end result was the theft of credentials, potential further compromise, and the risk of follow-on malware, financial loss, or operational disruption.
Kill Chain Progression
Initial Compromise
Description
Phishing emails mimicking Microsoft O365 lured users to input credentials on lookalike login pages, resulting in credential and session cookie theft.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Spearphishing Link
Credential Harvesting
Email Collection: Remote Email Collection
Valid Accounts: Cloud Accounts
Steal Web Session Cookie
User Execution: Malicious Link
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor Authentication for All Access to the CDE
Control ID: 8.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Monitoring & Logging
Control ID: 500.03, 500.14
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework and Incident Management
Control ID: Art. 9, Art. 10
CISA Zero Trust Maturity Model 2.0 – Continuous Identity Verification and Session Protection
Control ID: Identity Pillar: Authentication, Session Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
HIPAA Security Rule – Security Awareness and Training
Control ID: 45 CFR §164.308(a)(5)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Healthcare organizations face critical risk from RaccoonO365 phishing campaigns targeting Microsoft 365 credentials, compromising patient data and HIPAA compliance requirements.
Financial Services
Financial institutions vulnerable to credential theft operations enabling lateral movement and data exfiltration, requiring enhanced zero trust segmentation and egress security controls.
Government Administration
Government agencies at high risk from phishing-as-a-service attacks targeting Microsoft 365 environments, necessitating improved threat detection and multicloud visibility capabilities.
Information Technology/IT
IT sector organizations must implement enhanced east-west traffic security and encrypted communications to prevent credential harvesting and protect client infrastructure assets.
Sources
- Microsoft seizes hundreds of phishing sites tied to massive credential theft operationhttps://cyberscoop.com/microsoft-seizes-phishing-sites-raccoono365/Verified
- Microsoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing servicehttps://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/Verified
- Reactor Powers Microsoft’s Civil Action against RaccoonO365https://www.chainalysis.com/blog/reactor-powers-microsoft-civil-action-against-raccoono365/Verified
- Threat actors leverage tax season to deploy tax-themed phishing campaignshttps://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust segmentation, rigorous policy enforcement on egress, real-time threat detection, and workload isolation could have prevented credential theft, curtailed vault movement, disrupted exfiltration, and detected anomalous attack patterns. CNSF-aligned controls provide in-line enforcement and visibility, mitigating the spread and business impact of credential-based phishing attacks.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked outbound connections to known phishing domains.
Control: Zero Trust Segmentation
Mitigation: Limited attackers' ability to access privileged resources.
Control: East-West Traffic Security
Mitigation: Prevented unauthorized east-west movement between workloads.
Control: Threat Detection & Anomaly Response
Mitigation: Real-time alerts on suspicious C2 and session activities.
Control: Cloud Firewall (ACF)
Mitigation: Blocked or flagged suspicious outbound data transfers.
Reduced attacker dwell time and overall campaign impact.
Impact at a Glance
Affected Business Functions
- Email Communications
- User Authentication
- Data Security
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive user credentials, leading to unauthorized access to corporate systems and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress filtering and DNS/FQDN-based policy enforcement to prevent connections to known phishing and malicious domains.
- • Deploy zero trust network segmentation and identity-based access controls to limit privilege escalation and lateral movement after credential compromise.
- • Integrate threat detection and anomaly response tools capable of identifying session hijacking, risky authentications, and covert communication patterns.
- • Utilize cloud-native firewalls and traffic observability to monitor for and block suspicious data exfiltration from cloud workloads and SaaS environments.
- • Orchestrate Cloud Native Security Fabric controls for continuous, autonomous policy enforcement and real-time containment across multi-cloud identities, workloads, and network paths.



