ATT&CKReferencesSekoia Raccoon2 2022

Sekoia Raccoon2 2022

Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRaccoon Stealer

Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.

T1012
Query Registry
MalwareRaccoon Stealer

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.

T1020
Automated Exfiltration
MalwareRaccoon Stealer

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1027.007
Dynamic API Resolution
MalwareRaccoon Stealer

Raccoon Stealer dynamically links key WinApi functions during execution.

T1027.013
Encrypted/Encoded File
MalwareRaccoon Stealer

Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.

T1033
System Owner/User Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on the infected system owner and user.

T1041
Exfiltration Over C2 Channel
MalwareRaccoon Stealer

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1071.001
Web Protocols
MalwareRaccoon Stealer

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.

T1082
System Information Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information.

T1083
File and Directory Discovery
MalwareRaccoon Stealer

Raccoon Stealer identifies target files and directories for collection based on a configuration file.

T1087.001
Local Account
MalwareRaccoon Stealer

Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`.

T1105
Ingress Tool Transfer
MalwareRaccoon Stealer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.

T1113
Screen Capture
MalwareRaccoon Stealer

Raccoon Stealer can capture screenshots from victim systems.

T1119
Automated Collection
MalwareRaccoon Stealer

Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers.

T1124
System Time Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers victim machine timezone information.

T1213
Data from Information Repositories
MalwareRaccoon Stealer

Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service.

T1518
Software Discovery
MalwareRaccoon Stealer

Raccoon Stealer is capable of identifying running software on victim machines.

T1539
Steal Web Session Cookie
MalwareRaccoon Stealer

Raccoon Stealer attempts to steal cookies and related information in browser history.

T1555.003
Credentials from Web Browsers
MalwareRaccoon Stealer

Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.

T1560
Archive Collected Data
MalwareRaccoon Stealer

Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.