Raccoon Stealer is a malware-as-a-service infostealer operated in the cybercrime ecosystem and rented to affiliates on a subscription basis. It is designed to harvest sensitive data from infected systems, including login credentials, browser-stored information, payment card data, cryptocurrency wallet data, and large volumes of authentication cookies. By stealing session cookies in addition to usernames and passwords, it can enable account takeover without requiring re-entry of credentials and can in some cases bypass multi-factor authentication protections tied to active sessions.
The malware targets Windows environments and is commonly used as a follow-on payload delivered by other malware distribution operations and loaders. It has been observed delivered through social-engineering-driven campaigns and by malware loaders such as Batloader and PrivateLoader. Its role in criminal intrusion chains is typically focused on rapid collection and exfiltration of victim data for resale, reuse, or downstream fraud.
Operational reporting has linked Raccoon Stealer infections to centralized backend infrastructure used to aggregate stolen data from infected hosts. Observed collections associated with version 1.7.2 included victim account data, device details, cleartext passwords, and millions of authentication cookies, illustrating the malware’s emphasis on browser and session theft at scale. Victim data associated with these operations has included personal, workplace, social media, and government account access, making the malware relevant to both consumer and enterprise compromise scenarios.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The actors behind Water Minyades are known for delivering other malware during the last quarter of 2022, such as Qakbot, RaccoonStealer, and Bumbleloader via social engineering techniques.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaccoonStealer is an information-stealing malware focused on credential theft, with developers using generative AI to improve phishing portals.
Named as a payload historically dropped by PrivateLoader (no additional behavior details provided in this content).
Credential/data stealer delivered in Water Minyades-related campaigns.
An infostealer offered as a malware-as-a-service toolkit that steals login credentials, credit card information, cryptocurrency wallets, browser data, and authentication cookies from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.