Skip to content

Raccoon Stealer

Raccoon Stealer is a widely used Windows information stealer operated as a malware-as-a-service offering in the cybercrime ecosystem.

Profile source: Mallory opens in a new tab

Raccoon Stealer

Family profile

Raccoon Stealer is a widely used Windows information stealer operated as a malware-as-a-service offering in the cybercrime ecosystem. It is designed to harvest credentials and other sensitive data from infected systems, particularly from web browsers, and has been repeatedly associated with bulk stealer-log markets, access brokerage, and follow-on intrusions. The malware is known to collect saved browser passwords, cookies, autofill data, browsing-related information, stored payment-card data, screenshots, host profiling data, and files or directories specified by configuration received from command-and-control infrastructure. It communicates over HTTP, including HTTP POST requests, and downloads configuration data that governs collection behavior.

Raccoon Stealer has commonly been used in financially motivated crime operations and malware bundles alongside other commodity malware families such as loaders, miners, and additional stealers. Reported delivery methods include fake cracked-software and warez sites, fake installers, and related social-media promotion, with some campaigns using password-protected archives and anti-analysis features to reduce detection. In observed operations it has also appeared as one component of larger pay-per-install ecosystems that combine credential theft, persistence, proxying, and cryptocurrency mining.

The malware plays an important role in the criminal division of labor: stolen logs containing credentials and session material are sold or reused for account takeover, enterprise intrusion, and resale to other actors. Raccoon Stealer infections should therefore be treated as full credential and session compromise events. Public reporting indicates the service was disrupted in 2022 following action against its operator, but the family remains a well-known reference point in discussions of commodity infostealers and stealer-log enabled intrusion activity.

Capabilities

  • Credential Theft
  • Exfiltration
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • CH1
  • SG1

Leading providers

  • DigitalOcean, LLC1
  • WorkTitans B.V.1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)

ByteToBreach

Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)

Scattered Spider

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

GOLD HARVEST

GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.

LAUNDRY BEAR

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Storm-0501

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

Curious Serpens

"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."

MITRE ATT&CK

Raccoon Stealer in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1078 Valid Accounts T1113 Screen Capture T1105 Ingress Tool Transfer T1204 User Execution T1555 Credentials from Password Stores T1189 Drive-by Compromise T1539 Steal Web Session Cookie T1082 System Information Discovery T1562.001 Disable or Modify Tools T1497 Virtualization/Sandbox Evasion T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1567 Exfiltration Over Web Service T1056 Input Capture T1555.003 Credentials from Web Browsers T1557 Adversary-in-the-Middle T1589.001 Credentials T1102 Web Service T1560 Archive Collected Data T1036 Masquerading T1140 Deobfuscate/Decode Files or Information T1204.002 Malicious File T1486 Data Encrypted for Impact T1583 Acquire Infrastructure T1003 OS Credential Dumping T1083 File and Directory Discovery T1033 System Owner/User Discovery T1071.001 Web Protocols T1119 Automated Collection T1564 Hide Artifacts T1598 Phishing for Information T1087.004 Cloud Account T1592 Gather Victim Host Information T1497.001 System Checks T1012 Query Registry T1070.004 File Deletion T1027.013 Encrypted/Encoded File T1217 Browser Information Discovery T1027 Obfuscated Files or Information T1566 Phishing T1204.001 Malicious Link T1586 Compromise Accounts T1608.006 SEO Poisoning T1129 Shared Modules T1649 Steal or Forge Authentication Certificates T1195 Supply Chain Compromise T1614 System Location Discovery T1027.007 Dynamic API Resolution T1518 Software Discovery T1087.001 Local Account T1020 Automated Exfiltration T1213 Data from Information Repositories T1124 System Time Discovery T1556.006 Multi-Factor Authentication T1597.002 Purchase Technical Data T1133 External Remote Services T1078.002 Domain Accounts T1588.002 Tool

Reporting

Research mentioning Raccoon Stealer

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

Jul 21
Cyberveille

ByteToBreach : profil d'un opérateur de fuites de données actif depuis juin 2025 | CyberVeille

Romania’s National Agency for Cadastre and Land Registration (ANCPI) confirmed that the outage affecting its e-Terra cadastre and land registry platform was caused by a cyberattack, disrupting property and real-estate transactions while the agency worked to restore services. ANCPI said the application would likely remain unavailable until the end of the week and stated that, based on its ongoing investigation, data managed through its IT systems had not been compromised. At the same time, a threat actor using the alias ByteToBreach advertised alleged ANCPI data for sale on a dark web forum, claiming to have breached the agency’s internal network, stolen Romanian citizens’ cadastre and property records, copied GitLab servers and source code for core systems, and deployed ransomware. Those claims were not independently verified, but the actor has previously been profiled as a credible, opportunistic data-leak operator that targets high-impact organizations and monetizes stolen information through underground forums and public-facing channels.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.