Hacker NewsNotizie internazionaliNewsAltri videoVideos

Judge Jed Rakoff Closed the RaccoonO365 Civil Case in Default While Nigeria’s File Still Names Okitipi Samuel

Un giudice di Manhattan ha concluso la lotta civile contro RaccoonO365 senza un processo. La polizia della Nigeria ha ancora un nome diverso dal lato criminale dello stesso kit. Quei due fatti possono sedersi nella stessa settimana e lasciare ancora la persona che ha scritto il codice non testato in un tribunale che può bloccare una cella.

Il 18 maggio 2026, il giudice del distretto di stati uniti Jed S. Rakoff concesse a Microsoft Corporation e Health-ISAC un giudizio di default e un'ingiunzione permanente nel distretto meridionale di New York, caso 1:25-cv-07111. Gli imputati erano Joshua Ogundipe e John fa 1 a 4. Non sono apparsi. La predefinizione è ciò che fa un tribunale civile quando un partito citato salta la lotta. Non è una giuria che dice che una persona di nome ha commesso un crimine, e non è un biglietto aereo per un bacino nigeriano. L'ordine limita gli imputati RaccoonO365, i loro rappresentanti e le persone che agiscono con loro dall'accesso intenzionalmente ai computer protetti senza autorizzazione, tra cui altri limiti scritti nell'ingiunzione. Il docket mostra che il caso è terminato quel giorno.

Mesi prima, la Nigeria Police Force National Cybercrime Centre ha detto ai giornalisti che aveva prenotato Okitipi Samuel, chiamato anche Moses Felix, come sviluppatore del phishing infrastrutture. Spokesman Benjamin Hundeyin ha detto che gli ufficiali hanno lavorato dall'intelligenza passata da microsoft attraverso il fbi e il servizio segreto degli stati uniti. Raids in Lagos e Stati Edo ha prodotto computer portatili, telefoni e altri dispositivi. Altre due persone prese in quei reparti furono poi rilasciate. Hundeyin ha detto che gli investigatori non hanno trovato alcuna prova che quei due costruissero o gestissero la piattaforma, e li ha descritti come vittime del furto di identità. Punch ha riferito i tre nomi nella lista di arresto originale come Joshua, James e Okitipi Samuel, con i pickup posti tra il 20 settembre e il 4 ottobre 2025, e il pubblico Avvicinarsi a dicembre. Il rapporto pubblico non ha stabilito che l'uomo rilasciato chiamato Joshua è il Joshua Ogundipe Microsoft citato a New York. Trattare quei nomi come una persona inventerebbe un fatto che la dichiarazione di polizia e la denuncia di Microsoft non condividono.

Operation Trashpanda: Disrupting RaccoonO365

A storefront that rented the Microsoft logo

RaccoonO365 è stato venduto come un abbonamento, non come un exploit one-off. Gli acquirenti hanno pagato circa $355 per 30 giorni o $999 per 90 giorni, in criptovaluta solo. Il kit ha generato pagine di accesso che hanno copiato Microsoft, DocuSign, SharePoint, Adobe e maersk. Le esche appoggiate su fatture, payroll e temi di risorse umane, i messaggi un dipendente stanco è addestrato ad aprire. I canali di telegramma legati al negozio contavano più di 850 membri. I pagamenti di cripto registrati hanno superato 100.000 dollari. Un mittente potrebbe spingere lo stesso richiamo verso ben 9.000 obiettivi in un giorno.

Researchers who tracked the service from at least July 2024 say it harvested more than 5,000 Microsoft 365 credentials across 94 countries. The mechanic was an adversary-in-the-middle proxy. The fake page talked to Microsoft’s real login servers, so a victim who typed a password and approved a prompt handed over the password, the one-time code, and a live session cookie in the same motion. Cloudflare Turnstile challenges made the pages look like ordinary corporate gates. Cloudflare later said the paying customer base was mainly crews based in Russia. By late 2025 the operators were selling an add-on called RaccoonO365 AI-MailCheck, a filter meant to score which stolen mailboxes were worth keeping. Microsoft tracks the activity as Storm-2246. The September 2025 disruption, described inside the Digital Crimes Unit as Operation Trashpanda, is the subject of a SANS CTI Summit briefing by investigators Maurice Mason and Nick Monaco.

Three hundred thirty-eight domains, then a default

The police work followed a technical seizure. Microsoft’s Digital Crimes Unit, Cloudflare’s Cloudforce One, and Chainalysis used a Southern District of New York order to seize 338 domains in September 2025. Microsoft and Health-ISAC sued under the Computer Fraud and Abuse Act, the Racketeer Influenced and Corrupt Organizations Act, and the Electronic Communications Privacy Act. Microsoft told the court the operation had cost it more than $650,000. Investigators said a sloppy cryptocurrency wallet helped put a name on the crew. Seized sites were replaced with warning pages. Paying customers moved to new hosts, which is what a phishing-as-a-service shop does when a brand gets burned. The May 2026 default judgment is the civil ending of that same lawsuit, not a second, separate story. The Record e BleepingComputer laid out the Nigerian arrests when they were new. The Hacker News reported Samuel was accused of running the Telegram sales channel and hosting fake portals on Cloudflare with stolen or fraudulently obtained email accounts.

A captured Outlook session is not a trophy login. It is a seat inside payroll, vendor invoices, patient charts, and student records. Microsoft documented an April 2025 tax-themed blast that hit more than 2,300 U.S. organizations, including at least 20 hospitals and healthcare providers. From a live mailbox the next steps are familiar: watch the threads, send internal phishing that looks like a coworker, then open the door for ransomware. The same vendor-risk pattern shows up in The AEGIS Alliance reporting on the 700Credit breach that exposed nearly 6 million car buyers e il Mixpanel incident that put Pornhub Premium analytics in play.

Abuja’s statute and a docket that does not share a defendant list

Commissioner of Police Ifeanyi Uche, who heads the National Cybercrime Centre, told users not to treat unexpected login prompts as routine. Hundeyin said campaigns of this kind produced business email compromise, data theft, and losses across several countries. The kit did not need a zero-day. It needed one person willing to type a password into a page that looked like Microsoft.

Samuel faces allegations of identity theft, unlawful access, creation and distribution of malicious software, and related counts under Nigeria’s Cybercrimes Act of 2024. Early reporting put a preliminary court date around February 3, 2026. Nigerian authorities were also described as having frozen accounts worth about 250 million naira, on the order of $550,000, while mapping money mules. As of late September 2026, public reporting still does not show a completed criminal conviction of Samuel or a completed U.S. extradition of Ogundipe. The FBI’s interest in the alleged mastermind under the Computer Fraud and Abuse Act is a referral, not a rendered sentence. Judge Rakoff’s injunction can bind people who show up in a U.S. case. It cannot, by itself, put a defendant in a cell in Lagos.

That gap is why the names matter. Microsoft’s complaint says Ogundipe, a programmer it placed in Nigeria, likely wrote most of the code and worked with associates on development, sales, and support. Nigeria’s December briefing named Samuel as the principal developer and did not name Ogundipe. A civil default against a person who never answered the complaint does not resolve which of those descriptions a future criminal court will accept. Readers who want the cross-border pattern can look at The AEGIS Alliance file on how U.S. Treasury workstations were remotely accessed, and at the later account of how Google dismantled a shadow network that used phones as quiet infrastructure.

What actually breaks this product

Password-plus-text-message multi-factor authentication is the control RaccoonO365 was built to steal. A proxy that sits between the user and the real login page can relay both the password and the one-time code, then ride the resulting cookie. Passkeys and hardware security keys are harder to replay that way because the proof is bound to the real site, not to a lookalike. Checking the address bar before a password goes in, and reporting the message to the person who runs the tenant instead of clicking “verify your account,” is dull. It is also the reason a $355 Telegram subscription stops printing money.

A phishing-as-a-service shop that sells to clients on several continents will not be closed by one country’s press conference. Domain seizures raise the cost. They do not erase the customer list. The open question, after the default judgment and after Samuel’s booking, is whether the next kit keeps the raccoon sticker or just changes the brand on the same proxy. Until a criminal court tests the evidence against a specific person, the disruption is a pause. Related coverage lives on The AEGIS Alliance hacker news, tecnologiae notizie internazionali desks. The kit was cheap. The mailbox it opened was not.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Articoli Correlati

Lascia un commento

Il tuo indirizzo email non sarà pubblicato. I campi obbligatori sono contrassegnati *

Pulsante per tornare all'inizio