Agent Racoon is a .NET backdoor documented by Palo Alto Networks Unit 42 and used in a cluster of apparently related intrusions tracked as CL-STA-0002. Unit 42 assessed this activity with medium confidence as nation-state–aligned based on victimology, TTPs, and customized tooling. The intrusions targeted organizations in the Middle East, Africa, and the United States. Agent Racoon uses the DNS protocol as a covert command-and-control channel, with C2 domains following a pattern such as "[4 characters].telemetry.[domain].com" and queries using additional subdomains and IDNA/Punycode encoding. Reported capabilities include command execution, file upload, and file download. In observed activity, the malware did not include persistence by itself and was instead executed via scheduled tasks. Threat actors disguised Agent Racoon binaries as Google Update and Microsoft OneDrive updater executables. Unit 42 identified samples communicating with telemetry.geoinfocdn[.]com and observed earlier C2 use of telemetry.geostatcdn[.]com. Activity involving Agent Racoon was tracked back to July 2022. One reported sample had SHA-256 354048e6006ec9625e3e5e3056790afe018e70da916c2c1a9cb4499f83888a47 and a modified compilation timestamp of 2075/02/23 08:12:59 UTC. In the broader intrusion set, attackers staged tooling in temporary directories such as C:\Windows\Temp and C:\Temp, stole credentials, collected and exfiltrated email from Microsoft Exchange via PowerShell snap-ins, exfiltrated roaming profiles using 7-Zip dropped via certutil.exe, and used cleanmgr.exe for cleanup after sessions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Appendix A lists "Agent Racoon" under Malware.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware used by Phantom Taurus per the tool list; the content provides no further description.
A .NET backdoor that uses DNS as a covert C2 channel (IDNA/Punycode subdomains) with encrypted communications, supporting command execution and file upload/download; executed via scheduled tasks for persistence in observed intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.