Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

Posted on December 19, 2025December 19, 2025 By CWS

Dec 19, 2025Ravie LakshmananCybercrime / Regulation Enforcement
Authorities in Nigeria have introduced the arrest of three “high-profile web fraud suspects” who’re alleged to have been concerned in phishing assaults focusing on main companies, together with the primary developer behind the RaccoonO365 phishing-as-a-service (PhaaS) scheme.
The Nigeria Police Drive Nationwide Cybercrime Centre (NPF–NCCC) mentioned investigations carried out in collaboration with Microsoft and the Federal Bureau of Investigation (FBI) led to the identification of Okitipi Samuel, also referred to as Moses Felix, because the principal suspect and developer of the phishing infrastructure.
“Investigations reveal that he operated a Telegram channel by which phishing hyperlinks have been bought in trade for cryptocurrency and hosted fraudulent login portals on Cloudflare utilizing stolen or fraudulently obtained electronic mail credentials,” the NPF mentioned in a publish shared on social media.
As well as, laptops, cellular units, and different digital tools linked to the operation have been seized following search operations carried out at their residences. The 2 different arrested people haven’t any connection to the creation or operation of the PhaaS service, per the NPF.

RaccoonO365 is the title assigned to a financially motivated menace group behind a PhaaS toolkit that allows unhealthy actors to conduct credential harvesting assaults by serving phishing pages mimicking Microsoft 365 login pages. Microsoft is monitoring the menace actor underneath the moniker Storm-2246.
Again in September 2025, the tech big mentioned it labored with Cloudflare to grab 338 domains utilized by RaccoonO365. The phishing infrastructure attributed to the toolkit is estimated to have led to the theft of at the least 5,000 Microsoft credentials from 94 nations since July 2024.
The NPF mentioned RaccoonO365 was used to arrange fraudulent Microsoft login portals aimed toward stealing consumer credentials and utilizing them to achieve illegal entry to the e-mail platforms of company, monetary, and academic establishments. The joint probe has uncovered a number of incidents of unauthorized Microsoft 365 account entry between January and September 2025 that originated from phishing messages crafted to imitate reputable Microsoft authentication pages.

These actions led to enterprise electronic mail compromise, knowledge breaches, and monetary losses throughout a number of jurisdictions, the NPF added.
A civil lawsuit filed by Microsoft and Well being-ISAC in September has accused defendants Joshua Ogundipe and 4 different John Does of internet hosting a cybercriminal operation by “promoting, distributing, buying, and implementing” the phishing equipment to facilitate subtle spear-phishing and siphon delicate data.
The stolen knowledge is then used to gas extra cybercrimes, together with enterprise electronic mail compromise, monetary fraud, and ransomware assaults, in addition to commit mental property violations.

The event comes as Google filed a lawsuit towards the operators of the Darcula PhaaS service, naming Chinese language nationwide Yucheng Chang because the group’s chief together with 24 different members. The corporate is in search of a court docket order to grab the group’s server infrastructure that has been behind a large smishing wave impersonating U.S. authorities entities.
Information of the lawsuit was first reported by NBC Information on December 17, 2025. The event comes just a little over a month after Google additionally sued China-based hackers related to one other PhaaS service often called Lighthouse that is believed to have impacted over 1 million customers throughout 120 nations.

The Hacker News Tags:Arrests, Attacks, Developer, Linked, Microsoft, Nigeria, Phishing, RaccoonO365

Post navigation

Previous Post: North Korea’s Digital Surge: $2B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers
Next Post: WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

Related Posts

Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi The Hacker News
Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures The Hacker News
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks The Hacker News
The Unusual Suspect: Git Repos The Hacker News
AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar The Hacker News
New Self-Spreading Malware Infects Docker Containers to Mine Dero Cryptocurrency The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Targeting HubSpot Users in Targeted Phishing Attack
  • US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator
  • Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration
  • University of Sydney Data Breach Affects 27,000 Individuals 
  • New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Targeting HubSpot Users in Targeted Phishing Attack
  • US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator
  • Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration
  • University of Sydney Data Breach Affects 27,000 Individuals 
  • New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark