Customer Story Microsoft

How Microsoft DCU Took Phishing-as-a-Service Operators to Court and Won

Cryptocurrency tracing played a pivotal role in attributing illicit activity to a specific individual… we uncovered patterns and identified the exchanges used by the threat actor to convert illicit gains into usable funds.”

Challenge

By early 2024, a threat actor known as Storm-2246 (operating as RaccoonO365) had industrialized the phishing process. Through a “Phishing-as-a-Service” (PhaaS) model, they lowered the barrier to entry for cybercrime, allowing anyone, regardless of technical skill, to launch sophisticated attacks for a small fee.

The operation was prolific and high-stakes. RaccoonO365 kits were used to steal over 5,000 Microsoft credentials across 94 countries. The group specifically targeted the healthcare sector, putting sensitive patient data at risk. 

Their Telegram channel amassed over 800 members, facilitating at least $100,000 in illicit cryptocurrency payments. Using tools like Lynx Credential Capture and Postman Marshmallow, attackers could harvest credentials and bypass security detections, such as multi-factor authentication (MFA), using attacker-in-the-middle tactics. This approach functioned much like other types of Cybercrime-as-a-Service (CaaS), in which sophisticated cyberattacks have been turned into convenient, plug-and-play products that anyone can rent or buy, removing the need to actually know how to code. 

Solution

Microsoft’s Digital Crimes Unit (DCU) launched a multi-faceted investigation that combined undercover “test buys,” technical analysis, and advanced blockchain forensics.

  • Following the Digital Receipts
    The DCU performed controlled purchases of the phishing kits. Because every transaction leaves a permanent record on the blockchain, using Chainalysis Reactor, investigators could trace these payments across multiple chains,including Bitcoin, Ethereum, and Tron.
  • Exploiting Operational Security (OpSec) Errors
    The breakthrough came during a negotiation when the threat actor inadvertently shared a USDT (Tron) wallet address before quickly replacing it with an Ethereum address. This error allowed investigators to link the different wallets to the same operator and trace the funds to some Nigerian-based cryptocurrency exchanges.
  • A Historic Legal Precedent
    For the first time, Microsoft included cryptocurrency tracing as a central component of a civil legal action. By using Chainalysis Reactor, the DCU was able to distill complex, cross-chain transactions into clear, visual evidence that was simple, yet rigorous, enough to stand in court.

 

Results

The coordinated effort between Microsoft and its partners resulted in a total dismantling of the RaccoonO365 ecosystem, proving that “as-a-service” cybercrime can be systematically dismantled through collaboration.

How Chainalysis Enabled the Breakthrough

Chainalysis Reactor allowed the DCU to follow the money to the person behind the keyboard. Chainalysis was used to distill complex, cross-chain transactions spanning Bitcoin, Ethereum, and Tron into a clear, visual sequence. This provided the Southern District of New York with the courtroom-ready forensic evidence necessary to grant a historic civil court order.

Investigators were also able to unmask the operator’s true name identity. This allowed Chainalysis to link the phishing subscriptions directly to a specific user and known physical infrastructure. Additionally, analysis identified that the funds were flowing into specific Nigerian exchanges, pinpointing the cash-out location. This granular intelligence allowed investigators to move beyond digital footprints and pursue real-world attribution.

A Coordinated Disruption with Global Partners

Using the legal hooks provided by the DCU’s evidence, Microsoft, in partnership with Cloudflare, successfully seized 338 malicious domains, cutting off the attackers’ ability to communicate with victims. Global public-private cyber information sharing collaborative Health-ISAC played a critical role in victim protection by identifying impacted organizations within the healthcare sector, allowing for rapid mitigation and the protection of sensitive patient data. 

The digital trail established by Microsoft and Chainalysis was then handed to U.S. and Nigerian law enforcement, leading to the identification and arrest of the developers.

Get started with Chainalysis