Raccoon Stealer is a Windows information-stealing malware family first released in April 2019 and distributed through a malware-as-a-service operation. Subscribers receive an administration panel for configuring payloads, generating builds, and retrieving stolen information. It targets personal and business data across numerous browsers and applications, including saved passwords, authentication cookies, autofill information, payment-card details, browsing history, email data, and cryptocurrency wallet material. Its victims are distributed worldwide, with no exclusive industry focus.
Raccoon Stealer 2.0 emerged in June 2022 following disruption of the original operation. Initially identified by some researchers as RecordBreaker, the second version introduced a rebuilt C/C++ codebase and revised service infrastructure. It supports 32-bit and 64-bit Windows environments, obtains collection configuration and legitimate supporting libraries from command-and-control servers, and submits stolen information through HTTP POST requests. Its capabilities include collecting system fingerprints and installed-application inventories, capturing screenshots, and stealing files from accessible disks. The second version transmits newly collected items individually rather than waiting for collection to finish.
Observed distribution includes malvertising on adult websites, redirects to Fallout and RIG exploit kits, and delivery through Smoke Loader and the Phorpiex botnet. Exploit-kit campaigns leveraged CVE-2019-0752 in Internet Explorer and CVE-2018-15982 in Adobe Flash Player. Raccoon payloads have also been associated with BLISTER and protected using Rex3Packer. Some campaigns used Telegram channels to maintain access to command-and-control destinations despite blocking. Dutch authorities arrested Mark Sokolovsky in March 2022, and he was subsequently charged in connection with the malware-as-a-service operation. Coordinated law enforcement action dismantled infrastructure supporting the original version, but the operation later relaunched with Raccoon Stealer 2.0.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer. | Interestingly, this Smoke Loader instance also downloads Raccoon Stealer and ZLoader.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer. | Interestingly, this Smoke Loader instance also downloads Raccoon Stealer and ZLoader.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis showed that the attackers used the technique to distribute Raccoon stealer... They, in particular, used Telegram channels in order to bypass blocking of active C&C servers.
ServHelper is being installed onto the targeted systems using several different mechanisms, ranging from fake installers for popular software to using other malware families such as Raccoon and Amadey as the installation proxies.
Since the beginning of 2019, the Raccoon malware has been offered as malware-as-a-service on various cybercrime forums... In June 2022, a new version of the Raccoon stealer was identified in the wild... Initially, the malware was named “Recordbreaker” but was later identified as a revived version of Raccoon stealer.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
303 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
170 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer described as extracting cookies, authentication tokens and session IDs that attackers could reuse to hijack authenticated sessions. Its mention is illustrative, not evidence of involvement in Microsoft's account compromise.
A competing information stealer mentioned only for comparison with Vidar.
An information stealer delivered as part of the STANDOFF bundle to steal credentials and other victim data.
Referenced as another infostealer used by some traffers teams alongside Aurora.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.