Raccoon Stealer is a commodity Windows information stealer operated as a malware-as-a-service offering and widely used in financially motivated cybercrime. It is designed to harvest sensitive data from infected systems, especially browser-stored credentials, cookies, autofill data, browsing history, and saved payment-card information. Infections are commonly treated as full credential and session compromise events because the malware can steal both passwords and active browser session material. Raccoon Stealer also gathers host and user information, can capture screenshots, and can collect files and directories according to operator-supplied configuration before packaging and exfiltrating the stolen data to command-and-control infrastructure over HTTP, including HTTP POST requests.
Observed campaigns have distributed Raccoon Stealer through fake software and cracked-software download sites, warez-themed lures, YouTube promotion, and broader malvertising ecosystems. Delivery chains have included password-protected self-extracting archives and loaders that reduce scanning visibility. Some campaigns paired Raccoon with additional payloads such as clippers, cryptominers, malicious browser extensions, click-fraud bots, backdoors, and ransomware, reflecting its role in stacked criminal-service operations.
Raccoon Stealer has been associated with multiple cybercriminal ecosystems and has been used by access-oriented and extortion-linked actors, including operators connected to Scattered Spider and GOLD HARVEST activity, as well as other commodity intrusion chains. Its prevalence alongside families such as RedLine, Vidar, Lumma, and StealC illustrates its role in the industrialized infostealer market, where stolen logs are monetized directly or used to enable downstream account takeover, fraud, and ransomware intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
32 distinct techniques documented for this family, organized by ATT&CK tactic.
There is increasing interplay between social engineering and stolen credentials... These credentials can enable initial access directly or support more convincing social engineering attempts by allowing attackers to reference internal systems or mimic legitimate employee behavior.
There is increasing interplay between social engineering and stolen credentials... These credentials can enable initial access directly or support more convincing social engineering attempts by allowing attackers to reference internal systems or mimic legitimate employee behavior.
There is increasing interplay between social engineering and stolen credentials... These credentials can enable initial access directly or support more convincing social engineering attempts by allowing attackers to reference internal systems or mimic legitimate employee behavior.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Payloads disguised as pirated software; SFX headers manipulated to block static unpacking.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
There is increasing interplay between social engineering and stolen credentials... These credentials can enable initial access directly or support more convincing social engineering attempts by allowing attackers to reference internal systems or mimic legitimate employee behavior.
RC4-decrypts the Telegram channel description to recover the C2 gate address.
The .NET loader includes an anti-virtual-machine module.
DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.
The downloaded file was a VHD container which, when mounted, revealed Installer.bat, a batch file containing simple commands intended to raise execution privileges; add scanning exclusions for Windows Defender; and download and execute a remote batch script and an executable.
When successfully deployed and executed, information-stealing malware can harvest credentials (usernames, passwords, and session cookies) from infected environments and export them as logs to the attackers’ server.
Collects browser authentication cookies for session hijacking.
The content repeatedly describes malware and threat actors querying, enumerating, searching, reading, or checking Windows Registry keys and values, e.g., "ADVSTORESHELL can enumerate registry keys," "APT41 queried registry values to determine items such as configured RDP ports and network configurations," and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
T1087.004: Account Discovery: Cloud To establish a foundational understanding of the target environment, a threat actor might first locate the identities operating within it... AzureHound parameters that facilitate the MITRE technique Account Discovery: Cloud Account include the following: list users list devices list device-owners list service-principals list service-principal-owners
APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.
Confucius has used a file stealer to steal documents and images... Patchwork developed a file stealer to search C:\ and collect files with certain extensions... Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
91 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware sold as a service that harvests browser passwords, cookies, autofill and stored card data, can target cryptocurrency wallets via a bundled clipper update, retrieve or drop additional payloads, and is operated through a Tor-based C2 panel.
Инфостилер, упомянутый как пример malware, использующего кражу учетных данных из браузеров.
Named as an infostealer family involved in credential theft and resale within the cybercriminal ecosystem.
Named as an infostealer family involved in credential theft and monetization within the cybercrime ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.