Raccoon Stealer is a Windows information-stealing malware family operated as a malware-as-a-service offering since 2019. It is designed to harvest browser-stored secrets and other sensitive data at scale, including saved credentials, cookies, autofill data, payment card information, cryptocurrency wallet data, email and messenger data, browser extension data, screenshots, installed application inventories, and selected files from victim systems. Some variants also support downloading and executing additional payloads, making the malware useful both for bulk credential theft and as a follow-on access enabler.
The malware has been widely associated with cybercriminal distribution ecosystems rather than a single intrusion set. It has been delivered through cracked software and fake cheats, phishing and macro-enabled lure documents, exploit-kit-driven malvertising, and commodity loaders and pay-per-install services including SmokeLoader, PrivateLoader, Legion Loader, Buer Loader, GCleaner, InstallCapital, and Phorpiex. Campaign reporting also shows use of Telegram infrastructure to store or update real command-and-control information, helping operators rotate backend infrastructure and evade blocking.
Raccoon Stealer targets Windows hosts and is implemented in C or C++. It performs host profiling, gathers identifiers and system metadata, and then steals data from Chromium-based and Mozilla-based browsers using browser-related libraries and database access. Reported theft scope includes passwords, cookies, saved logins, browser form data, credit card data, and cryptocurrency wallet artifacts. Version 2, which re-emerged in 2022 after the original operation was disrupted, was rebuilt from scratch and expanded its theft coverage to browser extensions, files across disks, screenshots, and installed application data. Analysts have also observed command-and-control-delivered configuration, staged retrieval of legitimate DLL dependencies, and item-by-item exfiltration behavior.
Operationally, Raccoon Stealer has been linked to a large criminal ecosystem and to a major law-enforcement disruption in 2022. U.S. authorities charged Ukrainian national Mark Sokolovsky for alleged involvement in the service, and international partners dismantled infrastructure tied to the then-current version. The operators later relaunched the malware as Raccoon Stealer 2.0. Reporting indicates the service was rented on underground forums with subscriber access to an administration panel for build generation and retrieval of stolen data. The malware has remained a prominent commodity stealer frequently referenced alongside families such as RedLine, Vidar, and StealC, and stolen Raccoon logs have been used downstream for credential abuse, session hijacking, fraud, and access brokerage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer. | Interestingly, this Smoke Loader instance also downloads Raccoon Stealer and ZLoader.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer. | Interestingly, this Smoke Loader instance also downloads Raccoon Stealer and ZLoader.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis showed that the attackers used the technique to distribute Raccoon stealer... They, in particular, used Telegram channels in order to bypass blocking of active C&C servers.
ServHelper is being installed onto the targeted systems using several different mechanisms, ranging from fake installers for popular software to using other malware families such as Raccoon and Amadey as the installation proxies.
Since the beginning of 2019, the Raccoon malware has been offered as malware-as-a-service on various cybercrime forums... In June 2022, a new version of the Raccoon stealer was identified in the wild... Initially, the malware was named “Recordbreaker” but was later identified as a revived version of Raccoon stealer.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Malvertising campaigns leading to exploit kits are nowhere near as common these days... relying on drive-by downloads.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer.
According to the malware authors, the new Raccoon version was built from scratch using C/C++
The malware begins with resolving the required API’s dynamically through LoadLibrary and GetProcAddress.
Firstly malware binary drops into the temp directory in any random name “\AppData\Local\Temp\ecc322f22da7cee63fb2ee0bfd5df59c.exe”
The malware deletes all the files which are downloaded from the internet, after the information is sent to C2.
The sample uses the RC4 algorithm for decrypting the base64 strings stored in binary.
Raccoon Stealer is very popular since it steals a wide range of information from infected devices, such as stored browser credentials and information, credit cards, cryptocurrency wallets, email data, and various other types of sensitive data from numerous applications.
The data stolen by Raccoon Stealer 2.0 includes the following: ... Browser passwords, cookies, autofill data, and saved credit cards.
it proceeds to collect browser saved passwords, credit card details and cookies using the following dll Sqlite3.dll – to collect login id and passwords from chrome(ium) based browsers mozglue.dll/nss3.dll – to collects login id and passwords from firefox
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Since March, the FBI has been collecting some of the data stolen by cybercriminals using the Raccoon Stealer malware from infected computers. "While an exact number has yet to be verified, FBI agents have identified more than 50 million unique credentials and forms of identification..."
The data stolen by Raccoon Stealer 2.0 includes the following: ... Installed applications list.
Machine GUID is obtained from the registry key “HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography” under “MachineGUID”
The malware initially collects machine GUID, username and sends it to C2
The data stolen by Raccoon Stealer 2.0 includes the following: ... Individual files located on all disks.
Raccoon Stealer is very popular since it steals a wide range of information from infected devices, such as stored browser credentials and information, credit cards, cryptocurrency wallets, email data, and various other types of sensitive data from numerous applications.
The C2 also provides the malware with its configuration ... and then waits for individual POST requests that contain stolen information.
It sends a POST request to the decrypted C2 using an unusual User-Agent String “ record ”.
302 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
160 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A competing information stealer mentioned only for comparison with Vidar.
An information stealer delivered as part of the STANDOFF bundle to steal credentials and other victim data.
Referenced as another infostealer used by some traffers teams alongside Aurora.
Information stealer deployed as part of the Operation STANDOFF infection bundle.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.