ATT&CKSoftwareRaccoon Stealer

Raccoon Stealer

S1148

Malware.View on attack.mitre.org

About this malware

Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground forums. Raccoon Stealer has experienced two periods of activity across two variants, from 2019 to March 2022, then resurfacing in a revised version in June 2022.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.

T1012
Query Registry

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.

T1020
Automated Exfiltration

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1027.007
Dynamic API Resolution

Raccoon Stealer dynamically links key WinApi functions during execution.

T1027.013
Encrypted/Encoded File

Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.

T1033
System Owner/User Discovery

Raccoon Stealer gathers information on the infected system owner and user.

T1041
Exfiltration Over C2 Channel

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1070.004
File Deletion

Raccoon Stealer can remove files related to use and installation.

T1071.001
Web Protocols

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.

T1082
System Information Discovery

Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information.

T1083
File and Directory Discovery

Raccoon Stealer identifies target files and directories for collection based on a configuration file.

T1087.001
Local Account

Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`.

T1105
Ingress Tool Transfer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.

T1113
Screen Capture

Raccoon Stealer can capture screenshots from victim systems.

T1119
Automated Collection

Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers.

View all 24 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. S2W Racoon 2022 Open source
    S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.
  2. Sekoia Raccoon1 2022 Open source
    Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.