Raccoon Stealer is a cybercriminal malware-as-a-service operation centered on an infostealer sold to other threat actors since 2019. The operation is associated with Ukrainian national Mark Sokolovsky, who used aliases including raccoonstealer, Photix, and black21jack77777, and was charged and later sentenced for his role in the scheme. The service provided subscribers with malware builds and an administration panel, lowering the barrier to entry for credential theft and related cybercrime. The malware is designed to steal credentials and other sensitive data from compromised systems, including stored browser passwords, cookies, autofill data, credit card information, cryptocurrency wallet data, email-related data, and information from numerous applications. Later versions also supported theft of browser extension data, Telegram data, Discord tokens, screenshots, and selected files, and could deliver additional payloads. Stolen data from the operation was subsequently used in fraud, identity theft, and ransomware attacks affecting victims worldwide. Operationally, Raccoon Stealer has used anti-analysis and anti-debugging protections, dynamic API loading, custom string obfuscation, mutex checks, locale checks, system profiling, and command-and-control driven modular behavior. Reported techniques include API hooking, process and thread manipulation, sandbox and debugger detection, and selective execution controls. The malware was disrupted in March 2022 through joint law-enforcement action involving the United States, the Netherlands, and Italy, after which the operation briefly suspended activity. It later re-emerged in June 2022 as a rebuilt version, initially referred to as Recordbreaker before being identified as Raccoon Stealer v2, with a rewritten codebase, new backend and frontend components, and expanded data-theft capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware-as-a-service cybercrime operation that rented infostealer malware to other threat actors, enabling theft of credentials, cryptocurrency wallets, credit card data, email data, and other sensitive information from infected devices.
Operates an information-stealing malware-as-a-service platform rented to other threat actors, enabling theft of browser credentials, credit card data, cryptocurrency wallets, email data, and other sensitive information from infected devices.
Malware-as-a-service info-stealer operation distributing and actively developing Raccoon Stealer v2 to steal browser credentials, cookies, autofill and credit card data, cryptocurrency wallet data, Telegram and Discord data, screenshots, and to optionally launch additional payloads such as RATs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.