RecordBreaker, also known as Raccoon Stealer V2 or RaccoonStealerV2, is a Windows information-stealing malware family that emerged in 2022 as the successor to Raccoon Stealer and has been marketed under a malware-as-a-service model. It is used in broad criminal campaigns focused on credential and data theft, and has also been delivered by other malware ecosystems and loaders including Rugmi, Danabot, and dotRunpeX-related activity.
RecordBreaker is designed to harvest sensitive information from infected systems. Reported capabilities include theft of browser-saved credentials, cookies, Telegram data, banking information, cryptocurrency wallet data, installed-program inventories, screenshots, and general system information. Some variants query SQLite-backed local data stores to extract browser and application data, package stolen information for exfiltration, and communicate with command-and-control infrastructure using HTTP GET and POST requests. Multiple reports also describe retrieval of configuration data and auxiliary DLL components prior to theft activity.
The malware has been observed using process injection, including process hollowing into legitimate Windows processes, dynamic API resolution, mutex-based reinfection control, RC4 encryption for staged or collected data, and persistence via scheduled tasks. It can also download and execute additional payloads after initial compromise. In observed campaigns, follow-on payloads have included software intended to preserve the appearance of a legitimate crack as well as cryptocurrency miners.
Distribution has been strongly associated with social-engineering lures around cracked software, keygens, cheats, plugins, and pirated applications. Observed delivery methods include phishing websites masquerading as software-download portals, malicious links promoted through YouTube tutorial videos and compromised YouTube accounts, infected repositories, and compressed archive attachments. Victims are typically enticed into manually downloading and executing the malware under the guise of unauthorized software or installers.
RecordBreaker has also been associated with abuse of legitimate online services for malicious operations. It has been referenced alongside malware and threat actors that use GitHub for malicious communications or payload delivery, and separate reporting has documented additional payload retrieval from GitHub in RecordBreaker campaigns.
The malware primarily targets Windows systems and is used opportunistically against a wide victim pool, especially users seeking pirated software. Because stolen logs can include credentials, cookies, and financial data, infections can enable account compromise, fraud, cryptocurrency theft, and follow-on intrusion into enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
расшифровка паролей, куки-файлов, сохранённых карт (СС) хрома (AES GCM) теперь происходит на серверной части
The data stolen by Raccoon Stealer 2.0 includes the following: ... Installed applications list.
Discovery T1012 Query Registry The registry is used to gather system info, such as the operating system and currently-installed software.
Discovery T1057 Process Discovery If the process is running as SYSTEM, it will enumerate running processes.
I used the REST API to manage comments on issues and pull requests... built a GitHub-specific URL to post a comment on an issue, added a Bearer token header... | As you can see, any API service can be used as a C2 and Github is not the exception.
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware development trick 44: Stealing data via legit GitHub API. Simple C example. OceanLotus BitRAT RecordBreaker
RecordBreaker is mentioned as an additional payload distributed through Danabot.
A named malware example cited as using GitHub for malicious activity/C2-like operations.
An information stealer delivered by Rugmi.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.