نيجيريا تحتجز مطور الراكونو365 المزعوم بينما يُدعى (مايكروسوفت) ببدلة اليرك الجديدة

وحدة الجرائم الرقمية في (مايكروسوفت) أنفقت 2025 من سبتمبر مركز نيجيريا الوطني للجرائم السيبرانية قضى عام 2025 حجز رجل اسمه لم يكن على شكوى ميكروسوفت المدنية ولا يتوافق هذان الجدولان الزمنيان، وهذا الخطأ هو الآن الجزء الحي من ملف راكون أو 365.
Officers in Lagos and Edo States detained Okitipi Samuel, also known as Moses Felix and RaccoonO365, as the alleged developer of a phishing-as-a-service kit that sold counterfeit Microsoft 365 login pages for cryptocurrency. Two other people taken in the same sweeps were later released. Police said they found no evidence those two built or ran the platform. The man Microsoft had already sued in New York as the ringleader, Joshua Ogundipe of Benin City, was not named in the Nigerian police statement that followed the raids. Microsoft had referred him for international prosecution. His public whereabouts stayed unclear.
هذا التقسيم ليس حاشية هذا هو السبب في مضبوطات في مانهاتن وصحيفة حجز في لاغوس يمكن أن يكونا صحيحين
مكتب اشتراكات، وليس قرصان القبو الوحيد
RaccoonO365 was merchandised like software-as-a-service. Operators charged about $355 for 30 days and $999 for 90 days, payable only in crypto. Buyers received generated pages that copied Microsoft, DocuSign, SharePoint, Adobe, and Maersk sign-in screens. Finance, human resources, and invoice themes filled the rest of the lure. Telegram channels tied to the shop counted more than 850 members. Recorded crypto payments topped $100,000. Senders could hit as many as 9,000 targets in a day.
Researchers say the service ran from at least July 2024 and harvested more than 5,000 Microsoft 365 credentials across 94 countries. The technical trick was an adversary-in-the-middle proxy. The fake page talked to Microsoft’s real servers, so the kit could lift passwords, multi-factor codes, and live session cookies in one pass. Cloudflare Turnstile CAPTCHA screens made the pages look like ordinary corporate gates. Cloudflare later said the customer base was mainly Russia-based crews. By late 2025 the operators were pitching an add-on called RaccoonO365 AI-MailCheck, a filter meant to score which stolen mailboxes were worth keeping.
Microsoft tracks the crew as Storm-2246. In April 2026, Digital Crimes Unit investigators described the September disruption under the internal name Operation Trashpanda, walking through how branding, Telegram sales, and AI-assisted targeting lowered the cost of entry for people who could not write an exploit themselves. Details of the Nigerian probe were first laid out by السجل و BleepingComputer.
ثلاثمائة وثمانية وثلاثون منطقة سقطت أولاً
The police work followed a civil and technical takedown. Microsoft’s Digital Crimes Unit, Cloudflare’s Cloudforce One team, and Chainalysis used an order from the U.S. District Court for the Southern District of New York to seize 338 domains in September 2025. Microsoft and Health-ISAC sued Ogundipe and four John Does under the Computer Fraud and Abuse Act, RICO, and the Electronic Communications Privacy Act. Microsoft told the court the operation cost it more than $650,000. Investigators said a sloppy cryptocurrency wallet helped unmask the crew. Seized sites were swapped for warning pages. Paying customers migrated to new hosts, which is what PhaaS shops do when a brand gets burned.
Nigeria Police Force spokesman Benjamin Hundeyin said the December arrests grew out of intelligence from Microsoft, the FBI, and the U.S. Secret Service. Searches produced laptops, phones, and other devices. Samuel is accused of running the Telegram sales channel and hosting fake portals on Cloudflare with stolen or fraudulently obtained email accounts, according to أخبار هاكركما وضع حساب صحفي نيجيري لاحق جوشوا أوغونديبي وجيمس أوغونديبي في عمليات سابقة في لاغوس وإيدو في أيلول/سبتمبر وتشرين الأول/أكتوبر 2025، الأمر الذي يعمق فقط مسألة سبب هبط صامويل في بيان كانون الأول/ديسمبر بوصفه المطور الرئيسي.
ما سرق مايكروسوفت 365 صندوق بريد
A captured Outlook session is not a trophy login. It is a quiet seat inside payroll, vendor invoices, patient charts, and student records. Microsoft documented an April 2025 tax-themed blast that hit more than 2,300 U.S. organizations. At least 20 hospitals and healthcare providers were among the victims. From there the path is familiar: mailbox monitoring, internal phishing that looks like it came from a coworker, then ransomware. The same vendor-risk logic showed up in The AEGIS Alliance reporting on the 700 Credit الخرق الذي كشف حوالي 6 ملايين مشتري سيارات و حادثة (إكسبانل) التي وضعت محللي (بورنهوب بريميوم) في مسرحية.
Commissioner of Police Ifeanyi Uche, who heads the National Cybercrime Centre, told users not to treat unexpected login prompts as routine. Hundeyin warned that campaigns like this produced business email compromise, data theft, and losses across several countries. The kit did not need a zero-day. It needed a person who would type a password into a page that looked like Microsoft.
اتهامات في أبوجا ومرفأ مانهاتن لا يتشارك في قائمة المتهمين
Samuel faces identity theft, illegal access, and distribution of malicious software under Nigeria’s Cybercrimes Act of 2024. Early reporting put a preliminary Lagos High Court date around February 3, 2026. The FBI separately sought extradition of the alleged mastermind under the Computer Fraud and Abuse Act. Nigerian authorities were also said to have frozen accounts worth about 250 million naira, on the order of $550,000, while mapping money mules and mixers.
Public reporting through early September 2026 did not show a completed U.S. extradition of Ogundipe or a final Nigerian conviction of Samuel. Microsoft’s New York judgment does not, by itself, put anyone in a Lagos dock. That is why the FBI-Secret Service-NCCC channel matters more than the press release. A civil seizure can take domains. It cannot serve a warrant in Benin City.
ذات الصلة أخبار القراصنة على هذا المكتب تتبع نفس النمط في قضايا أخرى عبر الحدود، بما في ذلك الملف فيما بعد عن كيفية الوصول عن بعد إلى محطات العمل التابعة لخزانة الولايات المتحدة- تسافر مجموعات مواد التأليف أسرع من معاهدات المساعدة القانونية المتبادلة.
ما يوقف هذا المنتج
Password-plus-SMS multi-factor authentication is what RaccoonO365 was built to steal. Passkeys and hardware security keys are harder for an adversary-in-the-middle page to replay. Check the URL before a password goes in. Report the message to IT instead of clicking “verify account.” Those habits are dull. They are also the reason a $355 Telegram subscription stops being a business.
A PhaaS shop that sells to clients on several continents will not be closed by one country. The National Cybercrime Centre now treats that cooperation as policy, not a one-off favor. The open question is whether the next kit keeps the Raccoon name or just changes the sticker on the same proxy. Until Samuel’s case is tried and Ogundipe is either produced or formally written off, the disruption is a pause, not a funeral.
القراء الذين يريدون ضربة أوسع يمكن أن تبدأ مع تحالف التحالف التكنولوجيا و الأخبار الدولية مكاتب كانت الطقم رخيصة صندوق البريد الذي فتحه لم يكن









