Raccine is a defensive Windows tool referenced as being available on GitHub and designed to intercept use of vssadmin in order to prevent deletion of Volume Shadow Copies. The provided content mentions it in the context of a detection titled "Windows Raccine Scheduled Task Deletion" and explicitly states that the tool can block shadow copy deletion activity. This places it in the context of ransomware defense and anti-impact protections on Windows systems, specifically against behavior commonly used by ransomware to inhibit recovery. No additional high-confidence details about infection vectors, malicious capabilities, threat actor usage, targeted industries, or indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Anti-ransomware utility referenced in the context of scheduled task deletion, implying adversary attempts to disable or remove it.
Defensive utility mentioned as a mitigation that can block/interrupt shadow copy deletion (vssadmin) sometimes used in Ryuk infection chains; not malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.