ATT&CKReferencesSekoia Raccoon1 2022

Sekoia Raccoon1 2022

Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareRaccoon Stealer

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.

T1020
Automated Exfiltration
MalwareRaccoon Stealer

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1027.007
Dynamic API Resolution
MalwareRaccoon Stealer

Raccoon Stealer dynamically links key WinApi functions during execution.

T1027.013
Encrypted/Encoded File
MalwareRaccoon Stealer

Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.

T1033
System Owner/User Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on the infected system owner and user.

T1041
Exfiltration Over C2 Channel
MalwareRaccoon Stealer

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1070.004
File Deletion
MalwareRaccoon Stealer

Raccoon Stealer can remove files related to use and installation.

T1071.001
Web Protocols
MalwareRaccoon Stealer

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.

T1119
Automated Collection
MalwareRaccoon Stealer

Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers.

T1140
Deobfuscate/Decode Files or Information
MalwareRaccoon Stealer

Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers.

T1518
Software Discovery
MalwareRaccoon Stealer

Raccoon Stealer is capable of identifying running software on victim machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.