Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareRaccoon Stealer | Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key. |
| T1020 Automated Exfiltration |
MalwareRaccoon Stealer | Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1027.007 Dynamic API Resolution |
MalwareRaccoon Stealer | Raccoon Stealer dynamically links key WinApi functions during execution. |
| T1027.013 Encrypted/Encoded File |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection. |
| T1033 System Owner/User Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on the infected system owner and user. |
| T1041 Exfiltration Over C2 Channel |
MalwareRaccoon Stealer | Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration. |
| T1070.004 File Deletion |
MalwareRaccoon Stealer | Raccoon Stealer can remove files related to use and installation. |
| T1071.001 Web Protocols |
MalwareRaccoon Stealer | Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions. |
| T1119 Automated Collection |
MalwareRaccoon Stealer | Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers. |
| T1518 Software Discovery |
MalwareRaccoon Stealer | Raccoon Stealer is capable of identifying running software on victim machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.