Microsoft Disrupts RaccoonO365 Cyber Threat Group, Seizing 338 Websites Associated with Phishing Tactics
Microsoft has successfully disrupted a growing phishing service, RaccoonO365, which had targeted at least 20 U.S. health care organizations. The company used a court order to seize 338 websites associated with the cyber threat group, which offers subscription-based phishing kits that allow individuals to steal Microsoft 365 credentials through phishing tactics. The kits have stolen at least 5,000 Microsoft credentials from individuals in 94 countries since July 2024. This operation highlights a disturbing trend of cybercriminals using "initial access brokers" to steal credentials and artificial intelligence to accelerate the effectiveness of cyberattacks.
Key Takeaways:
- RaccoonO365, a cyber threat group, has targeted at least 20 U.S. health care organizations through phishing tactics.
- Microsoft used a court order to seize 338 websites associated with RaccoonO365, disrupting the group's operations.
- The phishing kits offered by RaccoonO365 have stolen at least 5,000 Microsoft credentials from individuals in 94 countries since July 2024.
- RaccoonO365 uses artificial intelligence to accelerate the effectiveness of cyberattacks, posing a direct threat to patient and community safety.
- The group offers subscription-based phishing kits that mimic official Microsoft communications, including emails, attachments, and websites.
- Credentials stolen through RaccoonO365 have enabled ransomware attacks against hospitals, emphasizing the need for continued social engineering training for staff.
- John Riggi, AHA national advisor for cybersecurity and risk, states that the operation highlights a disturbing trend of cybercriminals using "initial access brokers" to steal credentials and AI to accelerate the effectiveness of cyberattacks.
Statistics:
- 338 websites associated with RaccoonO365 were seized by Microsoft.
- 5,000 Microsoft credentials have been stolen by phishing kits offered by RaccoonO365 since July 2024.
- 94 countries have been affected by the phishing kits offered by RaccoonO365.
- At least 20 U.S. health care organizations have been targeted by RaccoonO365.
- The operation highlights a disturbing trend of cybercriminals using "initial access brokers" to steal credentials and AI to accelerate the effectiveness of cyberattacks.
Sources:
- American Hospital Association (AHA) - https://www.aha.org (no specific date mentioned)