By early 2024, a threat actor known as Storm-2246 (operating as RaccoonO365) had industrialized the phishing process. Through a “Phishing-as-a-Service” (PhaaS) model, they lowered the barrier to entry for cybercrime, allowing anyone, regardless of technical skill, to launch sophisticated attacks for a small fee.
The operation was prolific and high-stakes. RaccoonO365 kits were used to steal over 5,000 Microsoft credentials across 94 countries. The group specifically targeted the healthcare sector, putting sensitive patient data at risk.
Their Telegram channel amassed over 800 members, facilitating at least $100,000 in illicit cryptocurrency payments. Using tools like Lynx Credential Capture and Postman Marshmallow, attackers could harvest credentials and bypass security detections, such as multi-factor authentication (MFA), using attacker-in-the-middle tactics. This approach functioned much like other types of Cybercrime-as-a-Service (CaaS), in which sophisticated cyberattacks have been turned into convenient, plug-and-play products that anyone can rent or buy, removing the need to actually know how to code.
Microsoft’s Digital Crimes Unit (DCU) launched a multi-faceted investigation that combined undercover “test buys,” technical analysis, and advanced blockchain forensics.
The coordinated effort between Microsoft and its partners resulted in a total dismantling of the RaccoonO365 ecosystem, proving that “as-a-service” cybercrime can be systematically dismantled through collaboration.
How Chainalysis Enabled the Breakthrough
Chainalysis Reactor allowed the DCU to follow the money to the person behind the keyboard. Chainalysis was used to distill complex, cross-chain transactions spanning Bitcoin, Ethereum, and Tron into a clear, visual sequence. This provided the Southern District of New York with the courtroom-ready forensic evidence necessary to grant a historic civil court order.
Investigators were also able to unmask the operator’s true name identity. This allowed Chainalysis to link the phishing subscriptions directly to a specific user and known physical infrastructure. Additionally, analysis identified that the funds were flowing into specific Nigerian exchanges, pinpointing the cash-out location. This granular intelligence allowed investigators to move beyond digital footprints and pursue real-world attribution.
A Coordinated Disruption with Global Partners
Using the legal hooks provided by the DCU’s evidence, Microsoft, in partnership with Cloudflare, successfully seized 338 malicious domains, cutting off the attackers’ ability to communicate with victims. Global public-private cyber information sharing collaborative Health-ISAC played a critical role in victim protection by identifying impacted organizations within the healthcare sector, allowing for rapid mitigation and the protection of sensitive patient data.
The digital trail established by Microsoft and Chainalysis was then handed to U.S. and Nigerian law enforcement, leading to the identification and arrest of the developers.