Last seven days
- First activity
- Aug 23, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 2 hostnames
Raccoon Stealer is a Windows information-stealing malware family operated as a malware-as-a-service offering since 2019.
Profile source: Mallory opens in a new tabRaccoon Stealer
Raccoon Stealer is a Windows information-stealing malware family operated as a malware-as-a-service offering since 2019. It is designed to harvest browser-stored secrets and other sensitive data at scale, including saved credentials, cookies, autofill data, payment card information, cryptocurrency wallet data, email and messenger data, browser extension data, screenshots, installed application inventories, and selected files from victim systems. Some variants also support downloading and executing additional payloads, making the malware useful both for bulk credential theft and as a follow-on access enabler.
The malware has been widely associated with cybercriminal distribution ecosystems rather than a single intrusion set. It has been delivered through cracked software and fake cheats, phishing and macro-enabled lure documents, exploit-kit-driven malvertising, and commodity loaders and pay-per-install services including SmokeLoader, PrivateLoader, Legion Loader, Buer Loader, GCleaner, InstallCapital, and Phorpiex. Campaign reporting also shows use of Telegram infrastructure to store or update real command-and-control information, helping operators rotate backend infrastructure and evade blocking.
Raccoon Stealer targets Windows hosts and is implemented in C or C++. It performs host profiling, gathers identifiers and system metadata, and then steals data from Chromium-based and Mozilla-based browsers using browser-related libraries and database access. Reported theft scope includes passwords, cookies, saved logins, browser form data, credit card data, and cryptocurrency wallet artifacts. Version 2, which re-emerged in 2022 after the original operation was disrupted, was rebuilt from scratch and expanded its theft coverage to browser extensions, files across disks, screenshots, and installed application data. Analysts have also observed command-and-control-delivered configuration, staged retrieval of legitimate DLL dependencies, and item-by-item exfiltration behavior.
Operationally, Raccoon Stealer has been linked to a large criminal ecosystem and to a major law-enforcement disruption in 2022. U.S. authorities charged Ukrainian national Mark Sokolovsky for alleged involvement in the service, and international partners dismantled infrastructure tied to the then-current version. The operators later relaunched the malware as Raccoon Stealer 2.0. Reporting indicates the service was rented on underground forums with subscriber access to an administration panel for build generation and retrieval of stolen data. The malware has remained a prominent commodity stealer frequently referenced alongside families such as RedLine, Vidar, and StealC, and stolen Raccoon logs have been used downstream for credential abuse, session hijacking, fraud, and access brokerage.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ab38c4f49f7fbfefe9665466e276c5b6181f201ca54f74666030e38b9954a18 1cd56e19b8a4e21a6ea73949631ef80e8ba460d5ad527589e2c58964d2710054 5e4cb29836187e495329e0374acba583cefb50a9342b82ea86012d87b3ac9881 a87312122ffb2232249ac5cecf2418068c6d3bd7f33abd0b8dfce2d456e8e1af f9f09fbf412e4b4465dc900e7b28c14fc052c46aed1abcf6b0889ccc9ec765b7 9571a8826bbbc44202e717af7cfc4a66b896e3e44cbbbbd7ebac5db410be8d83 e053c5ad337b0c1b1728fe5416099565745b0df22a6e0de155e549556152862b 35bdbcd8f020d08fec92c8105592bc6a03c513492d568905396301e1f0742844 36bd97525993136f4a803d2c803c60efe59027d78f6a7a6504c95c6547411cdc 3e138230bd00c8d0878ffa7b5dc5e8827aa65f8f5a3d96450f0bd048d771b4a0 Reported operators
Analysis showed that the attackers used the technique to distribute Raccoon stealer... They, in particular, used Telegram channels in order to bypass blocking of active C&C servers.
ServHelper is being installed onto the targeted systems using several different mechanisms, ranging from fake installers for popular software to using other malware families such as Raccoon and Amadey as the installation proxies.
Since the beginning of 2019, the Raccoon malware has been offered as malware-as-a-service on various cybercrime forums... In June 2022, a new version of the Raccoon stealer was identified in the wild... Initially, the malware was named “Recordbreaker” but was later identified as a revived version of Raccoon stealer.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
Exploited software
MITRE ATT&CK
Reporting
AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.