Chasing After RacoonO365 IoCs Using DNS and Domain Intelligence
In September 2025, Cloudflare and Microsoft jointly disrupted RaccoonO365, a Phishing-as-a-Service (PhaaS) operation that had enabled cybercriminals to steal over 5,000 user credentials worldwide. Despite the takedown, traces of the infrastructure remain scattered across the internet.
In its threat brief, Cloudflare1 listed numerous indicators of compromise (IoCs), including three cryptocurrency addresses, 21 subdomains, and 77 domain names.
Our research team analyzed the domains tagged as IoCs, leading to the discovery of:















