Info Stealer

Raccoon Stealer

First seen: 2019-04 • Status: active

Currently Active Threat

Raccoon Stealer is like a digital pickpocket that criminals rent for about $200/month. It sneaks onto your computer through fake downloads or email attachments, then steals all your saved passwords, credit card info, and cryptocurrency. The developers were briefly stopped when one was arrested, but it came back even stronger as 'Raccoon v2'.

Overview

Raccoon Stealer is a prominent Malware-as-a-Service (MaaS) infostealer that targets credentials, cryptocurrency wallets, and sensitive data. After a brief hiatus in 2022 following the arrest of its main developer, Raccoon v2 emerged with improved capabilities and remains one of the most popular stealers on underground markets.

Also Known As

Raccoon, RaccoonStealer, Raccoon v2

How It Spreads

  • Phishing emails with malicious Office documents
  • Fake cracked software and game mods
  • Exploit kits on compromised websites
  • Malvertising campaigns
  • Trojanized legitimate software

What It Does

  • Steals browser credentials and autofill data
  • Extracts credit card information from browsers
  • Harvests cryptocurrency wallet data (50+ wallet types)
  • Captures screenshots and system information
  • Steals email client and FTP credentials
  • Exfiltrates Steam, Discord, and Telegram data

Is your business exposed?

Target Platforms

Windows 7, Windows 10, Windows 11

Detection Tips

  • Monitor for processes accessing multiple browser credential stores
  • Alert on rapid sequential file access to known wallet paths
  • Detect DLL injection into browser processes
  • Watch for connections to known Raccoon C2 infrastructure
  • Monitor for suspicious PowerShell downloading executables

MITRE ATT&CK Techniques

T1555, T1539, T1113, T1005, T1071.001

If You're Infected

  1. 1.

    Disconnect the infected system from the network

  2. 2.

    Reset all passwords saved in browsers on the infected machine

  3. 3.

    Cancel and replace any credit cards stored in browsers

  4. 4.

    Move cryptocurrency to new wallets immediately

  5. 5.

    Enable 2FA on all accounts, especially email and financial

  6. 6.

    Reimage the system from known clean backup

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required