S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRaccoon Stealer | Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes. |
| T1020 Automated Exfiltration |
MalwareRaccoon Stealer | Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1027.013 Encrypted/Encoded File |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection. |
| T1033 System Owner/User Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on the infected system owner and user. |
| T1041 Exfiltration Over C2 Channel |
MalwareRaccoon Stealer | Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration. |
| T1071.001 Web Protocols |
MalwareRaccoon Stealer | Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions. |
| T1082 System Information Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information. |
| T1083 File and Directory Discovery |
MalwareRaccoon Stealer | Raccoon Stealer identifies target files and directories for collection based on a configuration file. |
| T1105 Ingress Tool Transfer |
MalwareRaccoon Stealer | Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft. |
| T1113 Screen Capture |
MalwareRaccoon Stealer | Raccoon Stealer can capture screenshots from victim systems. |
| T1119 Automated Collection |
MalwareRaccoon Stealer | Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers. |
| T1124 System Time Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers victim machine timezone information. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers. |
| T1195 Supply Chain Compromise |
MalwareRaccoon Stealer | Raccoon Stealer has been distributed through cracked software downloads. |
| T1614 System Location Discovery |
MalwareRaccoon Stealer | Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.