Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2023, Google has been tracking a financially motivated actor it calls TRIPLESTRENGTH doing almost exactly this: stealing credentials and session cookies (some sourced from Racoon infostealer logs)...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
we can see how it obtains data that will be used later encrypted in RC4
it only has the ability to load other APIs/libraries with GetProcAddress + LoadLibraryW
The main information that RecordBreaker usually steals is: Browser (Cookies, User info, Passwords)
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer whose stolen credential and session-cookie logs were used as a source for cloud account compromise in the described activity.
Racoon is an infostealer malware that exfiltrates credentials, cookies, and other sensitive data from compromised systems.
Infostealer malware mentioned as targeting sensitive data such as browser-stored passwords, browsing history, clipboard data, and other selected files from compromised systems.
Referenced as another stealer whose sales were suspended, with MarsStealer likely being used as an alternative.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.