Raccoon Stealer is a widely used Windows information stealer operated as a malware-as-a-service offering in the cybercrime ecosystem. It is designed to harvest credentials and other sensitive data from infected systems, particularly from web browsers, and has been repeatedly associated with bulk stealer-log markets, access brokerage, and follow-on intrusions. The malware is known to collect saved browser passwords, cookies, autofill data, browsing-related information, stored payment-card data, screenshots, host profiling data, and files or directories specified by configuration received from command-and-control infrastructure. It communicates over HTTP, including HTTP POST requests, and downloads configuration data that governs collection behavior.
Raccoon Stealer has commonly been used in financially motivated crime operations and malware bundles alongside other commodity malware families such as loaders, miners, and additional stealers. Reported delivery methods include fake cracked-software and warez sites, fake installers, and related social-media promotion, with some campaigns using password-protected archives and anti-analysis features to reduce detection. In observed operations it has also appeared as one component of larger pay-per-install ecosystems that combine credential theft, persistence, proxying, and cryptocurrency mining.
The malware plays an important role in the criminal division of labor: stolen logs containing credentials and session material are sold or reused for account takeover, enterprise intrusion, and resale to other actors. Raccoon Stealer infections should therefore be treated as full credential and session compromise events. Public reporting indicates the service was disrupted in 2022 following action against its operator, but the family remains a well-known reference point in discussions of commodity infostealers and stealer-log enabled intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Payloads disguised as pirated software; SFX headers manipulated to block static unpacking.
In our case, the attacker entered the network over VPN (Username: Nexus, Password: Nexus123 - no MFA. Local admin.
RC4-decrypts the Telegram channel description to recover the C2 gate address.
checks anti-VM (VirtualBox, Wine, hyperviseur via NtQuerySystemInformation), checks anti-debugger
The downloaded file was a VHD container which, when mounted, revealed Installer.bat, a batch file containing simple commands intended to raise execution privileges; add scanning exclusions for Windows Defender; and download and execute a remote batch script and an executable.
When successfully deployed and executed, information-stealing malware can harvest credentials (usernames, passwords, and session cookies) from infected environments and export them as logs to the attackers’ server.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.
One component collected browser credentials, wallet-related information, and screenshots... stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
One component collected browser credentials, wallet-related information, and screenshots, while others enabled botnet control or cryptocurrency mining.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
98 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer delivered as part of the STANDOFF bundle to steal credentials and other victim data.
Information stealer deployed as part of the Operation STANDOFF infection bundle.
A broad credential and cookie harvesting infostealer that remains active in bulk stealer-log markets according to the content.
Infostealer mentioned as having been disrupted in 2022 following the operator's arrest; included as background context on takedowns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.