Raccoon Stealer is a Windows information-stealing malware family operated and sold under a malware-as-a-service model since 2019. It is widely known for harvesting browser-stored credentials, cookies, autofill data, payment card information, cryptocurrency wallet data, email and messenger data, browser extension data, screenshots, installed application inventories, and selected files from infected systems. The malware has also been observed downloading and executing additional payloads, making it useful both for bulk credential theft and as a follow-on access enabler in broader criminal operations.
The family has been distributed through multiple criminal delivery ecosystems, including cracked software and fake cheats, malvertising, exploit-kit chains, phishing with malicious macro documents, and third-party loaders such as SmokeLoader, Buer Loader, GCleaner, Legion Loader, PrivateLoader, and InstallCapital-linked delivery chains. Campaigns have also used Telegram infrastructure to publish or update real command-and-control locations, helping operators rotate backend infrastructure and evade blocking.
Raccoon Stealer is associated with Russian-speaking cybercrime activity and has been marketed to affiliates through subscription pricing and an administrative panel used to generate builds, configure theft targets, and retrieve stolen data. Law-enforcement action disrupted the original operation in 2022, after which the malware re-emerged as Raccoon Stealer 2.0. The second major version was rebuilt from scratch in C/C++ and introduced updated backend and frontend components along with expanded theft capabilities. Reported capabilities of version 2 include theft of browser passwords, cookies, autofill data, saved payment cards, cryptocurrency wallets, browser extensions, screenshots, installed application data, and arbitrary files, with configuration delivered from command-and-control infrastructure and supporting DLL components fetched as needed.
Raccoon Stealer primarily targets Windows hosts, including both 32-bit and 64-bit environments. It performs host fingerprinting and system profiling before exfiltration, and some variants use locale checks to avoid execution on systems configured for several CIS-region languages. The malware has been one of the more prominent commodity stealers in the cybercrime ecosystem and has been used at scale by entry-level and mid-tier threat actors for credential theft, session hijacking via stolen cookies, and monetization through resale of logs and downstream intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer. | Interestingly, this Smoke Loader instance also downloads Raccoon Stealer and ZLoader.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer. | Interestingly, this Smoke Loader instance also downloads Raccoon Stealer and ZLoader.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis showed that the attackers used the technique to distribute Raccoon stealer... They, in particular, used Telegram channels in order to bypass blocking of active C&C servers.
ServHelper is being installed onto the targeted systems using several different mechanisms, ranging from fake installers for popular software to using other malware families such as Raccoon and Amadey as the installation proxies.
Since the beginning of 2019, the Raccoon malware has been offered as malware-as-a-service on various cybercrime forums... In June 2022, a new version of the Raccoon stealer was identified in the wild... Initially, the malware was named “Recordbreaker” but was later identified as a revived version of Raccoon stealer.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Malvertising campaigns leading to exploit kits are nowhere near as common these days... relying on drive-by downloads.
Simple server-side cloaking performs the redirect to a Fallout exploit kit landing page which attempts to exploit CVE-2019-0752 (Internet Explorer) and CVE-2018-15982 (Flash Player) before dropping the Raccoon Stealer.
According to the malware authors, the new Raccoon version was built from scratch using C/C++
The malware begins with resolving the required API’s dynamically through LoadLibrary and GetProcAddress.
Firstly malware binary drops into the temp directory in any random name “\AppData\Local\Temp\ecc322f22da7cee63fb2ee0bfd5df59c.exe”
The malware deletes all the files which are downloaded from the internet, after the information is sent to C2.
The sample uses the RC4 algorithm for decrypting the base64 strings stored in binary.
Raccoon Stealer is very popular since it steals a wide range of information from infected devices, such as stored browser credentials and information, credit cards, cryptocurrency wallets, email data, and various other types of sensitive data from numerous applications.
The data stolen by Raccoon Stealer 2.0 includes the following: ... Browser passwords, cookies, autofill data, and saved credit cards.
it proceeds to collect browser saved passwords, credit card details and cookies using the following dll Sqlite3.dll – to collect login id and passwords from chrome(ium) based browsers mozglue.dll/nss3.dll – to collects login id and passwords from firefox
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Since March, the FBI has been collecting some of the data stolen by cybercriminals using the Raccoon Stealer malware from infected computers. "While an exact number has yet to be verified, FBI agents have identified more than 50 million unique credentials and forms of identification..."
The data stolen by Raccoon Stealer 2.0 includes the following: ... Installed applications list.
Machine GUID is obtained from the registry key “HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography” under “MachineGUID”
The malware initially collects machine GUID, username and sends it to C2
The data stolen by Raccoon Stealer 2.0 includes the following: ... Individual files located on all disks.
Raccoon Stealer is very popular since it steals a wide range of information from infected devices, such as stored browser credentials and information, credit cards, cryptocurrency wallets, email data, and various other types of sensitive data from numerous applications.
The C2 also provides the malware with its configuration ... and then waits for individual POST requests that contain stolen information.
It sends a POST request to the decrypted C2 using an unusual User-Agent String “ record ”.
302 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
158 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer delivered as part of the STANDOFF bundle to steal credentials and other victim data.
Referenced as another infostealer used by some traffers teams alongside Aurora.
Information stealer deployed as part of the Operation STANDOFF infection bundle.
A broad credential and cookie harvesting infostealer that remains active in bulk stealer-log markets according to the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.