Skip to content

Raccoon Stealer

Raccoon Stealer is a Windows information-stealing malware family operated as a malware-as-a-service offering since 2019.

Profile source: Mallory opens in a new tab

Raccoon Stealer

Family profile

Raccoon Stealer is a Windows information-stealing malware family operated as a malware-as-a-service offering since 2019. It is designed to harvest browser-stored secrets and other sensitive data at scale, including saved credentials, cookies, autofill data, payment card information, cryptocurrency wallet data, email and messenger data, browser extension data, screenshots, installed application inventories, and selected files from victim systems. Some variants also support downloading and executing additional payloads, making the malware useful both for bulk credential theft and as a follow-on access enabler.

The malware has been widely associated with cybercriminal distribution ecosystems rather than a single intrusion set. It has been delivered through cracked software and fake cheats, phishing and macro-enabled lure documents, exploit-kit-driven malvertising, and commodity loaders and pay-per-install services including SmokeLoader, PrivateLoader, Legion Loader, Buer Loader, GCleaner, InstallCapital, and Phorpiex. Campaign reporting also shows use of Telegram infrastructure to store or update real command-and-control information, helping operators rotate backend infrastructure and evade blocking.

Raccoon Stealer targets Windows hosts and is implemented in C or C++. It performs host profiling, gathers identifiers and system metadata, and then steals data from Chromium-based and Mozilla-based browsers using browser-related libraries and database access. Reported theft scope includes passwords, cookies, saved logins, browser form data, credit card data, and cryptocurrency wallet artifacts. Version 2, which re-emerged in 2022 after the original operation was disrupted, was rebuilt from scratch and expanded its theft coverage to browser extensions, files across disks, screenshots, and installed application data. Analysts have also observed command-and-control-delivered configuration, staged retrieval of legitimate DLL dependencies, and item-by-item exfiltration behavior.

Operationally, Raccoon Stealer has been linked to a large criminal ecosystem and to a major law-enforcement disruption in 2022. U.S. authorities charged Ukrainian national Mark Sokolovsky for alleged involvement in the service, and international partners dismantled infrastructure tied to the then-current version. The operators later relaunched the malware as Raccoon Stealer 2.0. Reporting indicates the service was rented on underground forums with subscriber access to an administration panel for build generation and retrieval of stolen data. The malware has remained a prominent commodity stealer frequently referenced alongside families such as RedLine, Vidar, and StealC, and stolen Raccoon logs have been used downstream for credential abuse, session hijacking, fraud, and access brokerage.

Capabilities

  • Credential Theft
  • Exfiltration
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 23, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
4 IP / 2 hostnames

Leading locations

  • RU2
  • US2
  • FR1
  • HU1

Leading providers

  • IHOR HOSTING LTD2
  • Amazon.com, Inc.1
  • MivoCloud SRL1
  • ServerAstra Kft.1
  • Trellian Pty. Limited1

Infrastructure traits

  • Hosting 6

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
FAKESECURITY

Analysis showed that the attackers used the technique to distribute Raccoon stealer... They, in particular, used Telegram channels in order to bypass blocking of active C&C servers.

TA505

ServHelper is being installed onto the targeted systems using several different mechanisms, ranging from fake installers for popular software to using other malware families such as Raccoon and Amadey as the installation proxies.

Raccoon Stealer group

Since the beginning of 2019, the Raccoon malware has been offered as malware-as-a-service on various cybercrime forums... In June 2022, a new version of the Raccoon stealer was identified in the wild... Initially, the malware was named “Recordbreaker” but was later identified as a revived version of Raccoon stealer.

Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)

ByteToBreach

Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)

Scattered Spider

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

GOLD HARVEST

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

LAUNDRY BEAR

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Storm-0501

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Curious Serpens

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Exploited software

Vulnerabilities linked to Raccoon Stealer

2 CVEs

MITRE ATT&CK

Raccoon Stealer in ATT&CK

100 distinct techniques

Techniques

100 techniques
T1010 Application Window Discovery T1105 Ingress Tool Transfer T1539 Steal Web Session Cookie T1005 Data from Local System T1071 Application Layer Protocol T1041 Exfiltration Over C2 Channel T1082 System Information Discovery T1059 Command and Scripting Interpreter T1113 Screen Capture T1555.003 Credentials from Web Browsers T1189 Drive-by Compromise T1649 Steal or Forge Authentication Certificates T1583.008 Malvertising T1190 Exploit Public-Facing Application T1056 Input Capture T1555 Credentials from Password Stores T1560 Archive Collected Data T1070.004 File Deletion T1587.001 Malware T1033 System Owner/User Discovery T1027.007 Dynamic API Resolution T1071.001 Web Protocols T1497.001 System Checks T1012 Query Registry T1140 Deobfuscate/Decode Files or Information T1574.007 Path Interception by PATH Environment Variable T1204.002 Malicious File T1102 Web Service T1566.002 Spearphishing Link T1566 Phishing T1036 Masquerading T1048 Exfiltration Over Alternative Protocol T1567.002 Exfiltration to Cloud Storage T1027 Obfuscated Files or Information T1059.001 PowerShell T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1608.006 SEO Poisoning T1583.003 Virtual Private Server T1090.003 Multi-hop Proxy T1021.004 SSH T1090 Proxy T1568 Dynamic Resolution T1218.009 Regsvcs/Regasm T1083 File and Directory Discovery T1059.003 Windows Command Shell T1078 Valid Accounts T1497 Virtualization/Sandbox Evasion T1588.001 Malware T1204 User Execution T1027.002 Software Packing T1552 Unsecured Credentials T1583.001 Domains T1614.001 System Language Discovery T1057 Process Discovery T1555.004 Windows Credential Manager T1115 Clipboard Data T1056.001 Keylogging T1552.002 Credentials in Registry T1622 Debugger Evasion T1087 Account Discovery T1203 Exploitation for Client Execution T1552.001 Credentials In Files T1106 Native API T1016 System Network Configuration Discovery T1055 Process Injection T1480.002 Mutual Exclusion T1614 System Location Discovery T1095 Non-Application Layer Protocol T1007 System Service Discovery T1003 OS Credential Dumping T1055.012 Process Hollowing T1137.006 Add-ins T1518 Software Discovery T1562.001 Disable or Modify Tools T1567 Exfiltration Over Web Service T1557 Adversary-in-the-Middle T1589.001 Credentials T1486 Data Encrypted for Impact T1583 Acquire Infrastructure T1119 Automated Collection T1564 Hide Artifacts T1598 Phishing for Information T1087.004 Cloud Account T1592 Gather Victim Host Information T1027.013 Encrypted/Encoded File T1217 Browser Information Discovery T1204.001 Malicious Link T1586 Compromise Accounts T1129 Shared Modules T1195 Supply Chain Compromise T1087.001 Local Account T1020 Automated Exfiltration T1213 Data from Information Repositories T1124 System Time Discovery T1556.006 Multi-Factor Authentication T1597.002 Purchase Technical Data T1133 External Remote Services T1078.002 Domain Accounts T1588.002 Tool

Reporting

Research mentioning Raccoon Stealer

Aug 12
Cylance Threatvector

Blog | Arctic Wolf

AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.