Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Raccoon Stealer is a widely used Windows information stealer operated as a malware-as-a-service offering in the cybercrime ecosystem.
Profile source: Mallory opens in a new tabRaccoon Stealer
Raccoon Stealer is a widely used Windows information stealer operated as a malware-as-a-service offering in the cybercrime ecosystem. It is designed to harvest credentials and other sensitive data from infected systems, particularly from web browsers, and has been repeatedly associated with bulk stealer-log markets, access brokerage, and follow-on intrusions. The malware is known to collect saved browser passwords, cookies, autofill data, browsing-related information, stored payment-card data, screenshots, host profiling data, and files or directories specified by configuration received from command-and-control infrastructure. It communicates over HTTP, including HTTP POST requests, and downloads configuration data that governs collection behavior.
Raccoon Stealer has commonly been used in financially motivated crime operations and malware bundles alongside other commodity malware families such as loaders, miners, and additional stealers. Reported delivery methods include fake cracked-software and warez sites, fake installers, and related social-media promotion, with some campaigns using password-protected archives and anti-analysis features to reduce detection. In observed operations it has also appeared as one component of larger pay-per-install ecosystems that combine credential theft, persistence, proxying, and cryptocurrency mining.
The malware plays an important role in the criminal division of labor: stolen logs containing credentials and session material are sold or reused for account takeover, enterprise intrusion, and resale to other actors. Raccoon Stealer infections should therefore be treated as full credential and session compromise events. Public reporting indicates the service was disrupted in 2022 following action against its operator, but the family remains a well-known reference point in discussions of commodity infostealers and stealer-log enabled intrusion activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Raccoon Stealer v1.7.2 (vol d’informations)
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
MITRE ATT&CK
Reporting
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Romania’s National Agency for Cadastre and Land Registration (ANCPI) confirmed that the outage affecting its e-Terra cadastre and land registry platform was caused by a cyberattack, disrupting property and real-estate transactions while the agency worked to restore services. ANCPI said the application would likely remain unavailable until the end of the week and stated that, based on its ongoing investigation, data managed through its IT systems had not been compromised. At the same time, a threat actor using the alias ByteToBreach advertised alleged ANCPI data for sale on a dark web forum, claiming to have breached the agency’s internal network, stolen Romanian citizens’ cadastre and property records, copied GitLab servers and source code for core systems, and deployed ransomware. Those claims were not independently verified, but the actor has previously been profiled as a credible, opportunistic data-leak operator that targets high-impact organizations and monetizes stolen information through underground forums and public-facing channels.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.