ATT&CKReferencesS2W Racoon 2022

S2W Racoon 2022

S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRaccoon Stealer

Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.

T1020
Automated Exfiltration
MalwareRaccoon Stealer

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1027.013
Encrypted/Encoded File
MalwareRaccoon Stealer

Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.

T1033
System Owner/User Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on the infected system owner and user.

T1041
Exfiltration Over C2 Channel
MalwareRaccoon Stealer

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1071.001
Web Protocols
MalwareRaccoon Stealer

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.

T1082
System Information Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information.

T1083
File and Directory Discovery
MalwareRaccoon Stealer

Raccoon Stealer identifies target files and directories for collection based on a configuration file.

T1105
Ingress Tool Transfer
MalwareRaccoon Stealer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.

T1113
Screen Capture
MalwareRaccoon Stealer

Raccoon Stealer can capture screenshots from victim systems.

T1119
Automated Collection
MalwareRaccoon Stealer

Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers.

T1124
System Time Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers victim machine timezone information.

T1140
Deobfuscate/Decode Files or Information
MalwareRaccoon Stealer

Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers.

T1195
Supply Chain Compromise
MalwareRaccoon Stealer

Raccoon Stealer has been distributed through cracked software downloads.

T1614
System Location Discovery
MalwareRaccoon Stealer

Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.