Raccoon Stealer, a malware-as-a-service infostealer sold on underground forums since 2019, was widely distributed through pirated software, fake cracks, game cheats, phishing, and large YouTube-based lure campaigns. Researchers tied deliveries to fake Microsoft Office and Adobe Photoshop cracks, hijacked YouTube accounts and video descriptions, and broader ecosystems using loaders such as Buer, SmokeLoader, and AveMaria RAT. Once executed, the malware stole browser passwords, cookies, autofill data, credit card details, cryptocurrency wallet files, screenshots, Telegram data, and other arbitrary files, while some campaigns also dropped secondary payloads including credential theft tools and a crypto miner.

Pull IOCs and campaign context straight into your stack.
26 events from the most recent confirmed update back to the earliest known activity.
CloudSEK analyzed a recent Raccoon Stealer v2 sample and disclosed that its packer used anti-analysis and anti-debugging techniques, including hooks on ntdll!DbgUiRemoteBreakin and ntdll!ZwProtectVirtualMemory. The report also detailed updated string encoding, victim profiling, C2-controlled theft modules, and optional payload delivery.
ZeroFox Intelligence discovered on June 4, 2022 that an information stealer distributed through the ProCrackerz fake crack site was actually Raccoon Stealer 2.0, also called Recordbreaker.
Zscaler reported that the analyzed Raccoon Stealer v2 sample retained debug information showing a compilation timestamp of 2022-05-26 13:58:25 UTC.
ZeroFox said that in May 2022, logs matching Recordbreaker activity were offered for sale with 'Raccoon Stealer V2.0' branding, supporting the link between the malware families.
ZeroFox reported that the earliest known sample of the stealer later identified as Raccoon Stealer 2.0 was uploaded to VirusTotal on April 19, 2022.
The original Raccoon Stealer malware-as-a-service operation shut down in March 2022, with its operators attributing the closure to the reported death of a lead developer during Russia's invasion of Ukraine. The remaining team said they planned to return with a second version of the malware.
Avast said that by February 17, 2022, its systems had observed more than 25,000 Raccoon-related samples, over 1,300 distinct configurations, and nearly 600,000 blocked attack attempts during the tracking period.
Avast's report measured Raccoon activity from March 3, 2021, starting the period in which it later counted more than 25,000 samples and nearly 600,000 attack attempts.
Sophos described a Raccoon Stealer campaign that used search-engine-optimized fake cracked-software sites and YouTube promotion to infect victims. The delivery chain also dropped secondary payloads including a SilentXMRMiner-based cryptocurrency miner and the QuilClipper clipboard hijacker, with VirusTotal seeing related xsph.ru payloads between October 2020 and April 2021.
Group-IB reported that the campaign's third wave began on June 29, 2020, with microsoft-cloud*.co.za domains used to deliver Raccoon Stealer samples.
Cyble reported that the Raccoon Stealer sample it analyzed carried a compilation timestamp of 2020-06-24 05:58:17.
Group-IB noted that the first Raccoon samples using a Telegram channel named blintick to retrieve encrypted replacement C2 addresses appeared on VirusTotal in late May 2020.
Group-IB said the FakeSecurity-linked malware distribution campaign began on February 19, 2020 and initially delivered Vidar stealer via malicious macro documents and phishing infrastructure.
In the campaign's second wave during 2020, attackers moved from distributing Vidar to distributing Raccoon Stealer through macro lure documents and related domains.
Group-IB said it discovered in summer 2020 a malware distribution campaign that abused Telegram channels to support delivery of Vidar and later Raccoon Stealer.
Researchers reported that the oldest observed Raccoon Stealer samples had timestamps from the end of April 2019, showing the malware was active in the wild by then.
Raccoon Stealer's authors stated that they began selling the malware on underground forums in April 2019, marking the start of its malware-as-a-service availability.
AhnLab ASEC confirmed a RecordBreaker campaign distributed through a likely hijacked YouTube account with more than 120,000 subscribers, using crack-themed links to deliver the malware.
Zscaler reported that a new variant, Raccoon Stealer v2, was released in early July 2022 as a major update to the malware family.
Zscaler said Raccoon Stealer v2 was first seen on July 3, 2022, marking the emergence of the new generation of the malware family.
Google said it was aware of the YouTube-based malware campaign and was taking action to block the threat actor's activity while flagging associated links to Safe Browsing.
Cluster25 reported a large-scale campaign using thousands of YouTube videos and channels to distribute password-stealing malware, including Raccoon Stealer, through links in video descriptions.
CyberArk Labs released a white paper detailing Raccoon Stealer's execution flow, including its CIS-language avoidance checks, Google Drive-based C2 retrieval, browser/email/wallet theft routines, exfiltration process, and self-deletion behavior. The report also published indicators of compromise and a YARA rule for detection.
Before publication of the report on the leak, the exposed Elasticsearch server disappeared, though it was unclear whether the provider or the operators removed it.
Bob Diachenko said he spent weeks trying to get the cloud provider to take down the exposed Elasticsearch server used to store stolen Raccoon data.
An exposed, unprotected Elasticsearch server leaked victim data believed to have been collected from hosts infected with RaccoonStealer version 1.7.2, including passwords and authentication cookies.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 289 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
19 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcegroup-ib.com
Open sourcecybereason.com
Open sourceasec.ahnlab.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcelp.cyberark.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.