Raccoon is a Russian-speaking cybercriminal operation best known for the Raccoon infostealer, also referred to as Mohazo and Racealer. Active since 2019, it operated as a malware-as-a-service offering and became widely used in underground crime ecosystems due to its low barrier to entry, aggressive marketing, and support for both Russian- and English-speaking customers. The operation is assessed to originate from Russia. Raccoon primarily conducts financially motivated credential and data theft. Its malware targets browser-stored credentials, cookies, autofill data, payment card information, email account data, cryptocurrency wallet data, screenshots, and host profiling information. Reported delivery methods include exploit kits, phishing documents with malicious macros, and trojanized software installers. The malware retrieves additional components from command-and-control infrastructure, harvests data from browsers and mail clients, collects system information, compresses stolen material, exfiltrates it, and then removes itself from the infected host. It has also been noted to avoid execution on systems configured for several CIS-region languages, a pattern commonly associated with Russian-speaking cybercrime operators. The actor has also been linked in reporting to socially engineered intrusions and extortion activity associated with UNC6783. In that activity, operators targeted business process outsourcing providers and help desk personnel, used phishing kits and fraudulent identity-provider login pages to steal credentials and bypass multifactor authentication, enrolled attacker-controlled devices to maintain access, and in some cases delivered remote access malware through fake security software. The campaign culminated in ransom or extortion notes sent to victims. Reporting has also associated the alias Mr. Raccoon with the theft of large volumes of support-ticket data following helpdesk-focused social engineering. Overall, Raccoon is characterized as a financially motivated cybercrime actor combining initial access tradecraft, credential theft, session hijacking, persistence, malware-enabled post-compromise collection, exfiltration, and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor linked to UNC6783 and associated with social engineering intrusions against help desk systems and extortion-related activity.
A Russian-speaking cybercrime team behind the Raccoon MaaS infostealer, aggressively marketing and operating a malware-as-a-service platform used to steal credentials, browser data, credit card information, email data, and cryptocurrency wallets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.