Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Reconnaissance T1589.001 Gather Victim Identity Information: Credentials Raccoon Stealer 2.0 retrieves stored credentials from targeted web browsers.
According to the malware authors, the new Raccoon version was built from scratch using C/C++
Loader: EXE/DLL/CMD/POWERSHELL. Вы можете использовать команды POWERSHELL для различных целей
Defense Evasion T1027.002 Software Packing Raccoon Stealer 2.0 can be found packed in the wild.
расшифровка паролей, куки-файлов, сохранённых карт (СС) хрома (AES GCM) теперь происходит на серверной части
Raccoon Stealer is very popular since it steals a wide range of information from infected devices, such as stored browser credentials and information, credit cards, cryptocurrency wallets, email data, and various other types of sensitive data from numerous applications.
The data stolen by Raccoon Stealer 2.0 includes the following: ... Browser passwords, cookies, autofill data, and saved credit cards.
Since March, the FBI has been collecting some of the data stolen by cybercriminals using the Raccoon Stealer malware from infected computers. "While an exact number has yet to be verified, FBI agents have identified more than 50 million unique credentials and forms of identification..."
The data stolen by Raccoon Stealer 2.0 includes the following: ... Installed applications list.
Discovery T1012 Query Registry The registry is used to gather system info, such as the operating system and currently-installed software.
Discovery T1057 Process Discovery If the process is running as SYSTEM, it will enumerate running processes.
The C2 also provides the malware with its configuration ... receives machine fingerprint data ... The data stolen by Raccoon Stealer 2.0 includes the following: Basic system fingerprinting info.
The data stolen by Raccoon Stealer 2.0 includes the following: ... Individual files located on all disks.
The C2 also provides the malware with its configuration ... and then waits for individual POST requests that contain stolen information.
Exfiltration T1020 Automated Exfiltration Data exfiltration is customizable by the actor through specified directories and file name patterns.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.